Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
DNSSEC support in systemd is broken for almost 5 years now (github.com/systemd)
8 points by jsiepkes on July 13, 2023 | hide | past | favorite | 5 comments


Because noone actually uses dnssec in practice.


More specifically most people do not use it on the client end-point. It's used by some resolvers which could be ones ISP DNS, some rando upstream DoH/DoT DNS, or a local DNS daemon on ones home network. To your point I disable it on my network for the lack of people signing their domains. It's one less thing that goes wrong [1].

Though to donselaar's point there will be governments and I suspect eventually fin-tech that will be regulated into signing and that's great especially for B2B/Gov2B connections that could use an extra form of verification. No harm in that. Optional for me, mandatory for more sensitive things and they are powerful enough to put pressure on DNS providers to make DNSSEC less error prone with time. Maybe once it has more adoption and is less error prone I may re-enable it.

[1] - https://ianix.com/pub/dnssec-outages.html


Well, roughly 30% globally and 60% in my country (The Netherlands) where the government mandates it for governmental systems. Source: https://stats.labs.apnic.net/dnssec


That's validation, not signatures, right?


∗crickets∗




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: