Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
indolering
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
31.
▲
by
indolering
7mo ago
> DNSSEC only protects the name lookup for a host, and TLS/HTTPS protects the entire session. It only provides privacy, it doesn't verify that the resolver didn't tamper with the record. >to the point where the root key
32.
▲
by
indolering
7mo ago
Okay, but after this I have to go back to work. You got a point: 1k isn't great and of course mainstream cryptographers will advocate for higher. That doesn't change that it's still acceptable within the existing securit
33.
▲
by
indolering
7mo ago
I advocate for DNSSEC in my personal life and you happen to jump on every DNSSEC HN submission and repeat your claims. So I post a link to my article debunking them. You won't engage in the substantive points here but insist that you
34.
▲
by
indolering
7mo ago
I worked at a DNS provider, does that count?
35.
▲
by
indolering
7mo ago
The benefits are huge: there are lots of attacks that DNSSEC trivially prevents and it would help secure more than just web browsers.
36.
▲
by
indolering
7mo ago
Then why the trolling? You claim to be interested in engaging in a substantive conversation or having done so in the past but when I try, you just insult me and announce that my advocacy for DNSSEC has inspired you to go hate on it more.
37.
▲
by
indolering
7mo ago
Yup.
38.
▲
by
indolering
7mo ago
You are going to complain that the key sizes are too small despite the guidelines being updated a long time ago. Then you will argue adoption of larger keys sizes is to low. Then you will argue that we should just not sign domain name aut
39.
▲
by
indolering
7mo ago
I mean, I guess the costs are paid for by the domain name fee. But at least it doesn't have to be a charitable activity covered by non-profits. The early HTTPS certs were especially worthless and price-gouging.
40.
▲
by
indolering
7mo ago
I did a large data analysis of DNS caching times across the web. Hyperscalers are the only ones who care and they fix that with insanely long DNS caching.
41.
▲
by
indolering
7mo ago
> You're on tilt. I'm upset that your incorrect arguments have gotten so much traction that the internet is a less safe place for it. > wrote a post disagreeing with my post, and I didn't go back and revise my post to c
42.
▲
by
indolering
7mo ago
No! Because it's totally possible for operating system vendors to flip that switch without requiring every upstream project to adopt key pinning. It's MUCH less infrastructure to upgrade.
43.
▲
by
indolering
7mo ago
RSA is still fine given that you can't break it in a year and we aren't worried about forward secrecy. Also, I worked for a DNS company. People stopped caring about ulta-low latency first connect times back in the 90s. You are cl
44.
▲
by
indolering
7mo ago
You claim in a sibling comment that you have engaged with my points, yet when I talk to you about it you just shut down the conversation . You really aren't going to respond to any of those points? You stand by your complaint DNS
45.
▲
by
indolering
7mo ago
True, but DNSSEC doesn't need to worry about forward secrecy and it doesn't need quantum protection until someone can start breaking keys in under a year. Hopefully we will find more efficient PQC by then.
46.
▲
by
indolering
7mo ago
You haven't been a web developer since you posted that article either, since you won't retract silly arguments on your website: "Government Controlled PKI!" - Governments own the domains, you just rent them. They can ki
47.
▲
by
indolering
7mo ago
Bad arguments and FUD when it was being rolled out. Sysadmins also don't want to touch working infra code, you can see that with AWS lagging on IPv6.
48.
▲
by
indolering
7mo ago
Mark Shuttleworth paid for his ride to the space station by selling HTTPS certs. The sad thing is that Mozilla and others have to spend millions bankrolling Let's Encrypt instead of using the free, high assurance PKI that is native to
49.
▲
by
indolering
7mo ago
As if DNS isn't a major contributing to A LOT of downtime. That doesn't mean it's not worth doing not investing in making deployment more seamless and less error prone.
50.
▲
by
indolering
7mo ago
Sorry, I thought my edit was fast enough. Yes it did hit HN and you just said, "I stand by what I wrote." and then complain about buggy implementations and downtime connected to DNSSEC. As if that isn't true for all technolo
51.
▲
by
indolering
7mo ago
That doesn't make it correct. Imagine if someone had said, "We don't need to secure HTTP, we'll just rely on E2E encryption and trust-on-first-use". I would really like it if we had a way to automatically cryptogr
52.
▲
by
indolering
7mo ago
Boy, how would cryptographically the ROOT of the internet make it more secure? Right here dude: https://easydns.com/blog/2015/08/06/for-dnssec/
53.
▲
by
indolering
7mo ago
Which is really unfortunate, since it's pretty easy to do.
54.
▲
by
indolering
7mo ago
It's great to see the free, cryptographically secure, and distributed keyval database that under-grids the entire internet being used to make it more secure. It's too bad lazy sys admins claim that it's not needed and spou
55.
▲
by
indolering
7mo ago
It would make them more secure and less vulnerable to attacks. But lazy sysadmins and large providers are too scared to do anything, in no small part due to your ... incorrect arguments against it.
56.
▲
by
indolering
7mo ago
No, no, you /refused/ to engage with me when I asked you to address these refutations of your arguments point-by-point. And it's sad that you have helped make weird workarounds more attractive than just doing the work to cry
57.
▲
by
indolering
7mo ago
> DNSSEC is moribund. You’ve clearly put a lot of effort into limiting adoption. I’d really value your thoughts on this response to your anti-DNSSEC arguments: https://easydns.com/blog/2015/08/06/for-d
58.
▲
by
indolering
7mo ago
Glad to see this finally getting some much needed love and attention!
59.
▲
by
indolering
7mo ago
Being able to detect these issues is just as important as preventing them.
60.
▲
by
indolering
8mo ago
If you get rid of data portability, then isn't it basically a Mattermost server? What is the alternative without going full Nostr where you have to manage all the cryptography yourself? Either you handle the cryptography for the user
More ›