PING

Calling time on DNSSEC: Part 1 of 2


Listen Later

In his regular monthly spot on PING, APNIC’s Chief Scientist Geoff Huston discusses DNSSEC and it's apparent failure to deploy at scale in the market after 30 years: Both as the state of signed zone uptake (the supply side) and the low levels of verification seen by DNS client users (the consumption side) there is a strong signal DNSSEC isn't making way, compared to the uptake of TLS which is now ubiquitous in connecting to websites. Geoff can see this by measurement of client DNSSEC use in the APNIC Labs measurement system, and from tests of the DNS behind the Tranco top website rankings.


This is both a problem (the market failure of a trust model in the DNS is a pretty big deal!) and an opportunity (what can we do, to make DNSSEC or some replacement viable) which Geoff explores in the first of two parts.


A classic "cliffhanger" conversation about the problem side of things will be followed in due course by a second episode which offers some hope for the future. In the meantime here's the first part, discussing the scale of the problem.


Read more about DNSSEC and TLS on the APNIC Labs website and the APNIC Blog:


  • Calling time on DNSSEC (Geoff Huston, APNIC Blog June 2024)
  • "Keytrap" attacks on DNSSEC (Geoff Huston, APNIC Blog June 2024)
  • DNS topics at RIPE88 (Geoff Huston, APNIC Blog June 2024)
  • The Tranco top website Rankings
  • DNSSEC validation client usage (APNIC Labs)
  • DNSSEC enabled domains from Cloudflare public DNS (APNIC Labs)
...more
View all episodesView all episodes
Download on the App Store

PINGBy APNIC

  • 5
  • 5
  • 5
  • 5
  • 5

5

4 ratings


More shows like PING

View all
Security Now (Audio) by TWiT

Security Now (Audio)

1,963 Listeners

Radiolab by WNYC Studios

Radiolab

43,833 Listeners

Risky Business by Patrick Gray

Risky Business

361 Listeners

The Amp Hour Electronics Podcast by The Amp Hour (Chris Gammell and David L Jones)

The Amp Hour Electronics Podcast

230 Listeners

The Talk Show With John Gruber by Daring Fireball / John Gruber

The Talk Show With John Gruber

3,115 Listeners

Network Break by Packet Pushers

Network Break

101 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

7,822 Listeners

IPv6 Buzz by Packet Pushers

IPv6 Buzz

33 Listeners

The Hedge by Russ White

The Hedge

15 Listeners

Ctrl+Alt+Azure by Tobias Zimmergren, Jussi Roine

Ctrl+Alt+Azure

12 Listeners

The Art of Network Engineering by Andy and friends

The Art of Network Engineering

81 Listeners

Flyvende tallerken by DR

Flyvende tallerken

31 Listeners

The Weekly Show with Jon Stewart by Comedy Central

The Weekly Show with Jon Stewart

10,200 Listeners

Risky Bulletin by risky.biz

Risky Bulletin

33 Listeners

Oxide and Friends by Oxide Computer Company

Oxide and Friends

47 Listeners