logoalt Hacker News

alfons_foobar • today at 5:44 PM • 1 reply • view on HN

You mean because the majority of the DNS is still unsigned?


Replies

tptacek • today at 6:10 PM

Yes, that, but also: virtually nobody has any actual security depending on DNSSEC at this point. DNSSEC isn't load-bearing, as it were. We had a DNSSEC-related outage in Germany a few months ago, and major providers (including all of Cloudflare) responded to it by disabling DNSSEC, which is something you don't do with security infrastructure.

I'm not being hyperbolic when I say the DNSSEC root keys could --- literally --- show up on Pastebin tonight and almost nobody would need to be paged.

➕ show 1 reply