logoalt Hacker News

cyberaxtoday at 7:15 PM1 replyview on HN

> DNSSEC mistakes take your entire domain off the Internet, as if it had never existed.

DNS mistakes take your entire domain off the Internet, as if it had never existed.

I'm preparing a proposal to add an advisory mode for DNSSEC. This will solve a lot of operational issues with its deployment. Enabling it will not have to be a leap of faith anymore.


Replies

tptacektoday at 7:18 PM

I haven't had to edit the DNS zones for most of my domains in many years. DNSSEC adds an expiring, rotating key change regime to it. If you screw it up, the screwup is cached everywhere, and the failure mode isn't like HTTPS, where you get an annoying popup: you just get NXDOMAIN, as if your domain never existed.

This isn't so much as a scary story I'm telling so much as it is an empirically observable fact; it's happened many times, to very important domains, over the last several years.

show 2 replies