Hacker News new | ask | show | jobs
by tptacek 51 days ago
I came to this thread with data. Your 20-at-the-moment DNS domains versus the current signing statistics of the Tranco Top 1000.

At the point where we're arguing about fail-open versus fail-closed, our premises are too far apart to get anywhere. We can part company here: I'm speaking, in part, for the people who believe that any viable security protocol must fail closed.

Plenty of security protocols have ultimately failed in the marketplace and been abandoned. DNSSEC is simply another one of them.

2 comments

You have deployed proof by assertion - I am powerless.

I am only describing my own experience and not pontificating on behalf of the world.

tptacek is HN's resident DNSSEC hater. I think he also hates IPv6.
I built the IPv6 private network system at Fly.io.
Let's keep the discussion civil please
That is civil. It's relevant and important to know that tptacek is present in every thread about DNSSEC and he always posts many comments opposing it, usually with little actual substance beyond "most people don't use it therefore it must suck"
Anyone can trivially use the search bar to see that your "little actual substance" claim is comically false. One of us built an actual app for this thread.
Your reasoning why DNSSEC is bad has been "most websites don't use it". Does that mean TLS was bad back when most websites didn't use it?
People have been trying to make DNSSEC a thing since 1995. Even when "most websites" didn't use TLS, basically all of ecommerce did: TLS has been load-bearing since the 1990s. Meanwhile, here in 2026, it is literally true that if the root keys landed on Pastebin tonight, almost nobody would need to be paged.