Post #2103950
2026-05-05 21:01 UTC
So apparently #DEnic has messed up #DNSSEC records for .de, and essentially all resolutions of .de domains now randomly fail. For example, Google DNS just gave me "RRSIG with malformed signature found for 76b2e6birnkv6aekmcbtnl5i4qkbji6a.de/nsec3 (keytag=33834)" in a failure response. With caching, this is probably going to take a while.
I'm still not convinced DNSSEC is a net positive technology. The impact crater when somebody messes it up is just way too large.
Replies (3)
-
@marius@kiessling.social 2026-05-05 21:14
@neverpanic that has also been our conclusion when we recently re-evaluated the need for DNSSEC. The threat of fucking up outweighs the threat mitigations we would largely get from DNSSEC.
-
@vincent@knuddelweide.de 2026-05-05 21:24
@neverpanic@chaos.social Hm, isn't the size of the crater the same if DENIC messes up something else that bricks downstream resolvers? Or am I missing something that makes DNSSEC worse?
-
@ErikUden@mastodon.social 2026-05-05 21:50
@neverpanic “what did we fuck up this time? why is mastodon.de not working?” so apparently the whole top level domain got nuked