23 points by speckx 2 days ago | 15 comments

Dan Kaminsky told me about the signing ceremony years ago (bless his heart, he was one of the people trusted with DNS security). Apparently, everyone on the signing committee flies to a central location carrying a hardware key. Then they take turns inserting their hardware key into a hardware security module. It's all done face-to-face because that's the only way to guarantee that human consent was granted properly at each step.

Each ceremony is recorded on video and distributed to the public. The last one was in August, 2026: https://www.youtube.com/watch?v=-QqYS3oLfL8&t=1s

The whole thing is performative (it's why the people with the key shares had them: to generate publicity for DNSSEC). The root keys could wind up on Pastebin tonight and almost nobody in the world would need to be paged.

The predictable rants from Thomas would mean more if you had an actual alternative. When I go back and look at your "Against DNSSEC" essay it's striking how the unchanging background is that you still think DNSSEC can't work and DNSSEC is still the only option we have.

2015 Thomas is pretty sure you mustn't trust the Web PKI. Which is weird because my guess is that 2026 Thomas recommends trusting it left and right, perhaps because...

2015 Thomas is sure the Web PKI or at least its Certificate Authorities will go away (they did not)

2015 Thomas is pretty sure we'll rely on Key Pinning. Those of you old enough to remember attempts to do this will remember how that went. Actually good stuff got killed off just by associating its ideas with the fiasco of HTTP Key Pinning.

2015 Thomas is very sure that it's crucial to keep your hostnames secret. You could of course buy hostname data in 2015 from several reputable (and many more disreputable) vendors but it's not clear whether Thomas knew that then but thought it best to pretend otherwise or whether he was ignorant.

Does "rant" just refer to any argument you disagree with? You responded to a 40-word comment just there.

What alternative is needed? The Internet has worked just fine without a centralized PKI for DNS name signatures for decades. The largest and best resourced security teams in the world as a rule do not enable DNSSEC. I've been saying this for over a decade and it has remained true. True-er over some of those years!

It's also super weird for you to try to dunk on key pinning here. Key pinning isn't a thing anymore because we have Certificate Transparency, and Certificate Transparency (and technologies like it) have been instrumental in killing multiple misbehaving certificate authorities.

You know what will never have anything resembling CT? The DNS. Google and Mozilla had to force CAs to adopt CT at the barrel of a gun. The gun, in the case of the domain name system, points the other direction.

> You responded to a 40-word comment just there.

And if it was the only one it wouldn't even deserve a comment. But it isn't because basically any mention of DNSSEC triggers your insistence that it can't work. All the stuff you've commended which didn't work went unmourned, but DNSSEC you're really animated about.

> The Internet has worked just fine without a centralized PKI for DNS name signatures for decades.

The Internet likewise worked "just fine" without a secure shell for decades. Tatu shipped his ssh command in 1995. Before that, and indeed for a year or five after as it was popularized, it was routine to rlogin to remote Unix machines - the user's unencrypted password was just sent over the wire like it's no big deal. But I'm going to guess that Thomas the Security Guy doesn't think rlogin is good enough in 2026 does he?

> Key pinning isn't a thing anymore because we have Certificate Transparency

Mozilla removed Key Pinning in Firefox 78. They added CT checks in Firefox 135. Hopefully it's pretty obvious to you that 135 was not before 78. HTTP Key Pinning was a fiasco. CT is to some extent coincidental timing rather than somehow a planned replacement and doesn't even attempt to address the same problems, because many of them were mirages.

> The gun, in the case of the domain name system, points the other direction.

Not at all. Browser vendor choices impact on the DNS and not vice versa. It's been that way since the beginning. The browsers don't look for the modern HTTP service record in DNS, so just make an A record for www to create a web server. And when they did finally decide to use HTTPS records they decided how to use them and when to use them, there was no way for DNS to impose that.

For the overwhelming majority of person-hours (or even Unix nerd person-hours) spent on the Internet we have had cryptographically secured remote shells.

Over all those hours, from the dawn of time until now, we have not had a centralized DNS PKI. The reason we haven't is that we don't need one. The way you know that is that virtually nothing has been compromised owing to a lack of it.

I honestly don't care what you think of key pinning. By 2016 I was advising clients against doing it. My point about your "pinning" timeline thing is that you sort of conveniently neglected to mention Certificate Transparency, pretending as if, when key pinning broke down, everyone just ignored the underlying problem. Obviously, no.

The great thing about DNSSEC is only those who care need care, those who don't seem to need to let everyone on HN know that's the case.

This kind of thing makes sense when DNSSEC is brought up incidentally somewhere, but makes a lot less sense when we're discussing the solemnity and gravity of the DNSSEC key signing ceremonies, for which it is actually useful context to know that they are entirely performative.

Really the only important thing to know about DNSSEC root key rollovers is that this is only the second one they've ever done, and the last one was kind of a fiasco --- they had to delay it an entire year for logistical reasons.

You mean because the majority of the DNS is still unsigned?

Yes, that, but also: virtually nobody has any actual security depending on DNSSEC at this point. DNSSEC isn't load-bearing, as it were. We had a DNSSEC-related outage in Germany a few months ago, and major providers (including all of Cloudflare) responded to it by disabling DNSSEC, which is something you don't do with security infrastructure.

I'm not being hyperbolic when I say the DNSSEC root keys could --- literally --- show up on Pastebin tonight and almost nobody would need to be paged.

> major providers (including all of Cloudflare) responded to it by disabling DNSSEC

Yeah I was very confused by this as well.

But then again, I think/hope that anyone relying on DNS / DNSSEC for security-related $THINGS is _probably_ running their own validating resolver.

[flagged]

Excellent Waveform podcast explaining it for general public: https://www.youtube.com/watch?v=26WvISI14g0

I'm requesting David's, Ellis's, and Adam's from Waveform: MKBHD Podcast attendance.

Context: https://www.youtube.com/watch?v=26WvISI14g0

[deleted]