@ska @dalias @lunarood I'd use DNSSEC if it didn't cause global unmitigatable outages every time I tried to use it
Conversation
Notices
-
Embed this notice
Xe :verified: (cadey@pony.social)'s status on Wednesday, 25-Jun-2025 00:34:38 JST Xe :verified:
- feld likes this.
-
Embed this notice
Rich Felker (dalias@hachyderm.io)'s status on Wednesday, 25-Jun-2025 00:36:52 JST Rich Felker
@cadey @ska @lunarood I'm not speaking about your experience which I don't know, but most of the "DNSSEC caused an outage" issues I've seen in the wild are essential "explicitly instructing systems not to trust anything but our designated private key, then fumbling said private key" issues.
This is basically "rigorous use of cryptographic chains of trust is essentially hard at some level", not "DNSSEC is hard".