4 ms·
Yes, I'm aware of the .nl situation in particular, and... it only underscores my point? If those .nl domains dropped off the Internet tomorrow, that (while of
by PreInternet01 3y ago
Yes, I'm aware of the .nl situation in particular, and... it only underscores my point?
If those .nl domains dropped off the Internet tomorrow, that (while of course very inconvenient for lots of people) wouldn't cause more than a tiny dip in global traffic. The benchmark here is how much of, say .com and .net combined, is signed. And that's around 4% (4.5M signed zones out of a total 170M, give or take).
Because of a well-intended mandate, most .nl domains are signed by their registrar, which generates and holds the private keys. So: the very same entity responsible for enabling domain delegation also secures that delegation. Virtually nobody generates and supplies their own DNSSEC keys when registering their .nl domain. So, a government looking for someone to lean on to modify a delegation, doesn't need to do that much extra work for such 'secure' zones, do they now?
From a consumer perspective, visiting digid.nl (signed, probably with their own keys, kept in a nice HSM somewhere!) vs. ah.nl (not signed) offers no meaningful extra privacy or security: when not using DoH, their ISP and anyone else in the middle will still have a pretty good idea what they're up to, and can strip off the 'hey, tell me about your signature' bits in any requests, leaving the client unable to tell the difference in the first place in most situations.
In case of a DNS hijack, the consumer security implications are exactly the same for both login (digid.nl) and shopping (ah.nl): their browser or app will refuse to connect, because DNS is already a negligible factor there, and it's the TLS certificate that makes the difference. That, combined with the very real danger that turning on DNSSEC makes a zone unresolvable for hours or even days on end, makes most people a bit wary about doing do. And they're absolutely right.
- jeroenhd 3y agoDNSSEC doesn't provide privacy. It was never designed to. If you want privacy, use ODoH. What it does offer, is tamper detection. I don't trust Cloudflare enough to always provide me with the right DNS data even if resolving the domain happens over TLS, and that's the part of the chain DNSSEC covers. DNS servers don't use DoH to resolve records, so the MitM risk remains. In my experience, the practical risks of enabling DNSSEC are minimal. Some broken (often Big Tech) DNS providers have had issues in the past (Amazon, notably) but every major DNS provider I've used has never let me down, and that includes some of the cheapest domain servers on the market. You may be as wary if you want to be, but .nl proves that the risks of DNSSEC are quite minimal in practice if the TLD registrar is competent.
- tptacek 3y agoHe just explained why it doesn't provide the tamper detection you think it does.