Elektrine lite

← Feed

@adamshostack@infosec.exchange

Post #2194331

2026-05-05 23:31 UTC

@jpmens@mastodon.social It's been a while since I dug into #dnssec but ... I thought the goal of a cryptographic trust infrastructure included that a company (Let's call them "quad9") can't interfere with someone else's #DNS records. (Let's call them ".de") But apparently, quad9 can just say "eh, ignore .de's policy? Someone help me understand? Added in edit: I understand the policy to be ".de has records authenticated with this key"?

Replies (3)

  • @acdha@code4lib.social 2026-05-06 01:58

    @adamshostack@infosec.exchange @jpmens@mastodon.social I'm perennially amazed that DNSSEC is still stuck in the previous century's model where your device is on a network managed by professional admins whom you trust absolutely. Even in the 90s it was cumbersome to block every improvement behind coordinated core infrastructure upgrades but we're now 3 decades into mainstream mobile computing where that assumption just does not hold at all.

    Open ##2194332

  • @letoams@defcon.social 2026-05-06 03:02

    @adamshostack@infosec.exchange @jpmens@mastodon.social not if you use them as forwarder - only when you use them as trust endpoint. It’s the users choice on how to configure their dns

    Open ##2194333

  • @paul_ipv6@infosec.exchange 2026-05-06 03:04

    @adamshostack@infosec.exchange @jpmens@mastodon.social i'm waiting for someone like mark andrews to chime in that if you use your own validating stub resolver in your device and you choose if you ignore validation failures, you are the one who decides, not one of the big quadX resolvers. ;)

    Open ##2194334