4 ms·
> DNSSEC is moribund. You’ve clearly put a lot of effort into limiting adoption. I’d really value your thoughts on this response to your anti-DNSSEC arguments:
by indolering 7mo ago
> DNSSEC is moribund.
You’ve clearly put a lot of effort into limiting adoption. I’d really value your thoughts on this response to your anti-DNSSEC arguments:
https://easydns.com/blog/2015/08/06/for-dnssec/ https://easydns.com/blog/2015/08/06/for-dnssec/
- tptacek 7mo agoI'm sure you can find several of those using the search bar. The argument has gotten a lot grimmer since 2015 --- DNSSEC lost deployment in North America over the last couple years. It didn't simply plateau off and stop growing: people have started turning it off. That corresponds with the success of CT in the WebPKI, with multi-perspective lookup, with the failure of DANE stapling in tls-wg, and with domain hijacking through registrar fixing.
- indolering 7mo agoNo, no, you /refused/ to engage with me when I asked you to address these refutations of your arguments point-by-point. And it's sad that you have helped make weird workarounds more attractive than just doing the work to cryptographically secure how domain names are delegated. It would make the entire stack sitting on top of DNS more secure. Instead we have to have reinvent the wheel for each protocol and outsource security to the TLS certificate vendors. What a waste.
- tptacek 7mo agoI feel pretty confident that the search bar refutes this claim you're making. What you're trying to argue is that I've avoided opportunities to argue about DNSSEC on HN. Seems... unlikely.
- indolering 7mo ago[flagged]
- gzread 7mo agoTo be clear, your argument is that DNSSEC is bad because people don't use it?
- tptacek 7mo agoYou have the causality reversed.
- gzread 7mo agoI think you are arguing that DNSSEC is bad, not that people don't use it. And the reason you're providing for why it's bad, is that people don't use it.
- tptacek 7mo agoI think that DNSSEC is bad. I know that people don't use it (I measure its usage, as you can see upthread). I suspect they don't use it because it's bad. But I guess I'm not as committed to that claim as I am to my first two claims.
- liveoneggs 7mo agoDNSSEC breaks DNS - your link posts all of its benefits and most of them are "make dns do other stuff!" DNS is already bad enough on its own without shoe-horning a bunch of other junk on top of it.