Advertisement
Advertisement
⚡ Community Insights
Discussion Sentiment
80% Positive
Analyzed from 813 words in the discussion.
Trending Topics
#dns#dnssec#records#desec#https#free#service#affordable#domains#support
Discussion Sentiment
Analyzed from 813 words in the discussion.
Trending Topics
Discussion (30 Comments)Read Original on HackerNews
So I did. No silly miniscule restrictions.
> […] our mission is to improve Internet security by increasing the adoption of DNSSEC. [We therefore expect users to enable DNSSEC for their domains.
> Would you be willing to do that?
Wanting to increase the adoption of DNSSEC is fair, but couldn’t this be all self-serve? It’s almost as if they don’t want people to use them.
As an aside (though this certainly applies to deSEC) it's strange to me how so many DNS services (free or paid) struggle to import simple Bind zone files, often either giving a vague error ("one or more records could not be imported"), mangling records, or even just silently omitting records. Parsing a zone file has some gotchas, but it doesn't seem like it should be that hard.
https://news.ycombinator.com/item?id=49568579
Weird timing?
https://sockpuppet.org/blog/2015/01/15/against-dnssec/
I mean, if your definition of "affordable" is free, then sure.
But for the record there are other affordable EU suppliers who do DNSSEC:
[0] https://bunny.net/dns/ [1] https://www.rcodezero.at/solutions/enterprise [2] https://www.netnod.se/dns/find-a-partnerhttps://www.ptrdns.net/
Looks like it's the glue records that point to the actual server?
What kind of security threat does a migration to such a service actually mitigate?
If they were truly a "sovereign EU" kind of project then they'd be on .eu domain, not have security advisors from Virginia, and so on.
Nevertheless it's good to see that the decoupling-from-your-allies movement that US citizens have initiated is so scary that they have to set up these kind of fake EU alternatives with some local figureheads.
It looks like they are open to adding the feature and open to outside contributions: https://github.com/desec-io/desec-stack/issues/579