Elektrine lite

← Feed

@neverpanic@chaos.social

Post #2103950

2026-05-05 21:01 UTC

So apparently #DEnic has messed up #DNSSEC records for .de, and essentially all resolutions of .de domains now randomly fail. For example, Google DNS just gave me "RRSIG with malformed signature found for 76b2e6birnkv6aekmcbtnl5i4qkbji6a.de/nsec3 (keytag=33834)" in a failure response. With caching, this is probably going to take a while. I'm still not convinced DNSSEC is a net positive technology. The impact crater when somebody messes it up is just way too large.

Replies (3)

  • @marius@kiessling.social 2026-05-05 21:14

    @neverpanic that has also been our conclusion when we recently re-evaluated the need for DNSSEC. The threat of fucking up outweighs the threat mitigations we would largely get from DNSSEC.

    Open ##2169198

  • @vincent@knuddelweide.de 2026-05-05 21:24

    @neverpanic@chaos.social Hm, isn't the size of the crater the same if DENIC messes up something else that bricks downstream resolvers? Or am I missing something that makes DNSSEC worse?

    Open ##2169201

  • @ErikUden@mastodon.social 2026-05-05 21:50

    @neverpanic “what did we fuck up this time? why is mastodon.de not working?” so apparently the whole top level domain got nuked

    Open ##2169203