Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Not only has it not been "debunked", but DNSSEC's own proponents openly acknowledge that the DNSSEC hierarchy is littered with 1024-bit RSA keys; see the chain-extension fiasco on the TLS working group mailing list. Or, see the stats you yourself posted to this thread a few days ago, which included key breakdowns. Further, despite the fact that DNSSEC uses outmoded P-curve ECC, and that modern signature schemes aren't even implemented for it, curve usage in DNSSEC is a tiny fraction of all keys.

The author of this post is simply wrong; what's more, he was wrong five years ago, and the situation has not improved.



Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: