6 ms·
Cloudflare has now disabled DNSSEC validation on their 1.1.1.1 resolver: https://www.cloudflarestatus.com/incidents/vjrk8c8w37lz https://www.cloudflarestatus.co
by tom1337 5mo ago
Cloudflare has now disabled DNSSEC validation on their 1.1.1.1 resolver: https://www.cloudflarestatus.com/incidents/vjrk8c8w37lz https://www.cloudflarestatus.com/incidents/vjrk8c8w37lz
- cluckindan 5mo agoIf it turns out the DNSSEC issue was caused by threat actors, this downstream effect could very well have been the reason to do it.
- amluto 5mo agoIt is indeed a bit sad that Cloudflare had to turn off DNSSEC completely. But I completely understand that they don't have a production-ready, tested path to override DNSSEC validation for only some domains.
- vendemiat 5mo agoSorry! status message was not clear. DNSSEC validation is temporarily disabled only for .de domains.
- tptacek 5mo agoThat's not much better!
- fastest963 5mo ago[flagged]
- tptacek 5mo agoIt didn't originally say that. They added the clarification just a few minutes ago. The guidelines ask you not to ask people these kinds of questions, for what it's worth.
- jonah-archive 5mo agoOriginally it said: --- The issue has been identified as a DNSSEC signing problem at DENIC, the organization responsible for the .DE top-level domain. Cloudflare has temporarily disabled DNSSEC validation on 1.1.1.1 resolver in order to allow .DE names to continue to resolve. DNSSEC validation will be re-enabled when the signing problems at DENIC are known to have been resolved. --- (and in case it changes again, now it says) --- The issue has been identified as a DNSSEC signing problem at DENIC, the organization responsible for the .DE top-level domain. Cloudflare has temporarily disabled DNSSEC validation for .de domains on 1.1.1.1 resolver (as per RFC 7646) in order to allow .DE names to continue to resolve. DNSSEC validation will be re-enabled when the signing problems at DENIC are known to have been resolved. See RFC 7646 for more details: https://datatracker.ietf.org/doc/html/rfc7646 https://datatracker.ietf.org/doc/html/rfc7646 ---
- tptacek 5mo agoThe RFC 7646 thing here is the funniest possible addition. This is the greatest day.
- tptacek 5mo agoWelp. I think can call it on DNSSEC now.
- amluto 5mo agoHahaha. You wish :-p
- tptacek 5mo agoIt's a pretty hard argument to work around: WebPKI certificates should go in the DNS, and also the largest DNS providers might at any moment decide not to validate DNSSEC anymore to get through an outage.
- pocksuppet 5mo agoIf there's going to be a single point of failure in front of your website, that single point of failure may as well be the only single point of failure instead of having two single points of failure, and it's probably important that people can't spoof responses.
- akerl_ 5mo agoNobody had to hack it. A system at DENIC broke, and so Cloudflare turned off DNSSEC validation for all of their users accessing .de. If DNSSEC was actually important for the security model of those users, that would be a huge deal.
- phicoh 5mo agoIf DNSSEC is part of your security model, you want local validation. Not relying on third party resolver that you don't have a contract with. Beyond that, DNS has the AD bit. If you need DNSSEC secure data (for example for the TLSA record), then when Cloudflare turns off DNSSEC validation, the AD bit will be clear and things will stop working.
- liveoneggs 5mo agoWe only disabled SSL on all the websites in one country for a little bit.. I'm sure those credit card numbers were perfectly safe over the wire
- weird-eye-issue 5mo agoThey didn't disable SSL you dingus.
- liveoneggs 5mo agoit was an analogy to try highlighting how silly "security" is when it's opt-in and any intermediary can just disable it
- weird-eye-issue 5mo agoI'm not sure you know how analogies work
- acdha 5mo agoThat comparison really makes the contrast clear: losing TLS would’ve put millions of people either into full downtime or immediately at significant risk (you can’t uncapture data). Losing DNSSEC, however, placed no one at risk and improved uptime. There’s a reason why one of the two has roughly 10% adoption after three decades and the other is high 90-something percent.
- account42 5mo agoThis seems like it should be the bigger news here. Disappointing knee jerk reaction from Cloudflare.
- petee 5mo agoTemporarily is a fairly important word to include with that link