Dan Kaminsky told me about the signing ceremony years ago (bless his heart, he was one of the people trusted with DNS security). Apparently, everyone on the signing committee flies to a central location carrying a hardware key. Then they take turns inserting their hardware key into a hardware security module. It's all done face-to-face because that's the only way to guarantee that human consent was granted properly at each step.
Cloudflare has a nice article documents the process: https://www.cloudflare.com/learning/dns/dnssec/root-signing-...
I'm requesting David's, Ellis's, and Adam's from Waveform: MKBHD Podcast attendance.
Context: https://www.youtube.com/watch?v=26WvISI14g0