Post #2169201
2026-05-05 21:24 UTC
@neverpanic@chaos.social Hm, isn't the size of the crater the same if DENIC messes up something else that bricks downstream resolvers? Or am I missing something that makes DNSSEC worse?
Replies (1)
-
@neverpanic@chaos.social 2026-05-05 21:39
@vincent That's correct, but evidently getting DNSSEC key rollovers right is hard, i.e., deploying it increases the risk that you'll mess something up. They need to do all the existing DNS serving stuff anyway, doing DNSSEC correctly *in addition* is a net increase in risk of getting it wrong.