310
you are viewing a single comment's thread
view the rest of the comments
[-] signofzeta@lemmygrad.ml 13 points 10 months ago

As soon as everyone signs their zones with DNNSEC, we can implement DANE to use self-signed certificates safely, and all our problems will go away, world peace will be achieved, and food will taste better.

[-] Chobbes@lemmy.world 2 points 10 months ago

I still don't understand the resistance to DNSSEC. It's just the right solution to the problem (or something like it is). Most of the arguments I've seen against it are just "the governments and three letter agencies control the TLDs!!" which like... Sure. But even with the usual CA infrastructure all of the trust depends upon the TLDs anyway. Like... If you are a TLD and control the root DNS servers you can obviously redirect any domain to wherever you want and get a LetsEncrypt certificate for any domain under the TLD anyway? Maybe somebody would notice, but it's probably just as likely that somebody would notice them messing around with DNSSEC (and then there would even be cryptographic proof of foul play?)

[-] c0mbatbag3l@lemmy.world 2 points 10 months ago

Will my cock grow a bit, too?

[-] signofzeta@lemmygrad.ml 3 points 10 months ago

Yes, and the RRSIG record will prove that it hasn’t been tampered with.

this post was submitted on 02 Oct 2023
310 points (93.8% liked)

Sysadmin

7445 readers
1 users here now

A community dedicated to the profession of IT Systems Administration

No generic Lemmy issue posts please! Posts about Lemmy belong in one of these communities:
!lemmy@lemmy.ml
!lemmyworld@lemmy.world
!lemmy_support@lemmy.ml
!support@lemmy.world

founded 1 year ago
MODERATORS