PING

Calling time on DNSSEC part 2 of 2


Listen Later

In his regular monthly spot on PING, APNIC’s Chief Scientist Geoff Huston continues his examination of DNSSEC. In the first part of this two-part story, Geoff explored the problem space, with a review of the comparative failure of DNSSEC to be deployed by zone holders, and the lack of validation by the resolvers. This is visible to APNIC labs from carefully crafted DNS zones with validly and invalidly signed DNSSEC states, which are included in the Labs advertising method of user measurement.


This second episode offers some hope for the future. It reviews the changes which could be made to the DNS protocol, or use of existing aspects of DNS, to make DNSSEC safer to deploy. There is considerable benefit to having trust in names, especially as a "service" to Transport Layer Security (TLS) which is now ubiquitous worldwide in the web.


Read more about DNSSEC and TLS on the APNIC Labs website and the APNIC Blog:

  • Calling time on DNSSEC (Geoff Huston, APNIC Blog, June 2024)
  • 'Keytrap' attacks on DNSSEC (Geoff Huston, APNIC Blog, June 2024)
  • DNS topics at RIPE 88 (Geoff Huston, APNIC Blog, June 2024)
  • The Tranco list
  • DNSSEC validation client usage (APNIC Labs)
  • DNSSEC-enabled domains from Cloudflare public DNS (APNIC Labs)
...more
View all episodesView all episodes
Download on the App Store

PINGBy APNIC

  • 5
  • 5
  • 5
  • 5
  • 5

5

4 ratings


More shows like PING

View all
This American Life by This American Life

This American Life

90,932 Listeners

The Changelog: Software Development, Open Source by Changelog Media

The Changelog: Software Development, Open Source

290 Listeners

Security Now (Audio) by TWiT

Security Now (Audio)

2,010 Listeners

The Everything Feed - All Packet Pushers Pods by Packet Pushers

The Everything Feed - All Packet Pushers Pods

195 Listeners

LINUX Unplugged by Jupiter Broadcasting

LINUX Unplugged

268 Listeners

Risky Business by Patrick Gray

Risky Business

372 Listeners

Network Break by Packet Pushers

Network Break

101 Listeners

Python Bytes by Michael Kennedy and Brian Okken

Python Bytes

215 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,057 Listeners

The Hedge by Russ White

The Hedge

16 Listeners

Risky Bulletin by risky.biz

Risky Bulletin

44 Listeners

N Is For Networking by Packet Pushers

N Is For Networking

21 Listeners