← Back to context

Comment by tptacek

4 days ago

This is a very strange definition of "dangerous".

I'm mostly thinking about dangerous from the security point of view. I agree that it might not be the best from the operational point of view. DNSSEC in its current state makes DNS updates even more risky than they are, I agree with that.

  • You remember what CIA stands for, right?

    • In order for an attacker to reduce a site's Availability via DNS they must alter the records received by resolvers.

      If they can do that, they can just refuse to send the records at all (or mangle them such that they are ignored). DNSSEC makes the situation no worse.

      It does, however, increase Integrity.

      For the record, the 'A' in CIA refers to resilience against some party's purposeful attempt to make something unavailable. It does not stand for Areliability or Asimplicity.

      3 replies →