logoalt Hacker News

tptacek • today at 6:10 PM • 1 reply • view on HN

Yes, that, but also: virtually nobody has any actual security depending on DNSSEC at this point. DNSSEC isn't load-bearing, as it were. We had a DNSSEC-related outage in Germany a few months ago, and major providers (including all of Cloudflare) responded to it by disabling DNSSEC, which is something you don't do with security infrastructure.

I'm not being hyperbolic when I say the DNSSEC root keys could --- literally --- show up on Pastebin tonight and almost nobody would need to be paged.


Replies

alfons_foobar • today at 8:28 PM

> major providers (including all of Cloudflare) responded to it by disabling DNSSEC

Yeah I was very confused by this as well.

But then again, I think/hope that anyone relying on DNS / DNSSEC for security-related $THINGS is _probably_ running their own validating resolver.