Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I just spent the better half of an hour to debug unbound and the pihole because I thought it's a me problem...

Good news though, if you add domain-insecure: "de" to your unbound config everything works fine



I don't even enable DNSSEC in Unbound. There just isn't enough adoption yet for me to feel like I am missing out on something, yet.

"Cloudflare Radar data shows 8.11% of domains are signed with DNSSEC, but only 0.47% of queries are validated end-to-end." [1]

Zones I may care about:

- Amazon.com: unsigned

- My banks: unsigned

- Hacker News: unsigned

- Email that I do not host: unsigned

- My power companies billing: unsigned

- I found some! id.me and irs.gov are signed.

[1] - https://technologychecker.io/blog/dnssec-adoption


The Tranco list is an academic research project to generate a "top N zones" list. Here's the portion of the top 1000 that is signed:

https://dnssecmenot.fly.dev/


That's cool, ty for that. The only one I put credentials into is Amazon it is unsigned. [1] There probably needs to be a DNSSECv2 .vbis that reduces risk somehow to get more adoption.

[1] - https://dnssec-analyzer.verisignlabs.com/amazon.com


For what it's worth, technically we're already on something like DNSSEC-ter or DNSSEC-quater. -bis was back in the early 2000s with the typecode roll. It was really called DNSSEC-bis!


It was really called DNSSEC-bis!

That's too funny. I was just kidding. Back in the day Ericsson always added that to their upgraded product lines (Including GSM and what-not)


Right, it's OSI/ITU-speak, and it's ironic to see it applied at IETF.


Do we know what their root mistake was? I've studied and deployed DNSSEC, and as I see it, the current version is pretty much the simplest thing that could possibly work, given the way DNS works.


The root cause of the disruption has not yet been fully identified. DENIC’s technical teams are working intensively on analysis and on restoring stable operations as quickly as possible.

That's their current official statement. I could guess but I would rather wait until they have an official statement. I would imagine they must know but they are probably going back and forth with their legal team to word it very carefully, or at least that is what I would be doing if I were in their situation.


Just before the outage happened I updated multiple client servers. That was a very stressfull hour trying to figure out why nothing works.


SAMEEEEE !!!


Same haha




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: