Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> Which of the criticisms in that article don't stand? What's changed?

Which of the rebuttals in the link I gave don’t stand?

> Adoption of DNSSEC has barely budged since I wrote it.

According to this graph, DNSSEC adoption seems to now be roughly 16×, i.e. 1600%, of what it was when you wrote it:

https://www.verisign.com/resources/dnssec-tools/dnssec-score...

 help



See the comment from 'dsl upthread.

As for stats: https://dnssecmenot.fly.dev/

It is not surprising that European registrars have added millions of new names nobody is ever going to visit, all of them signed by default at their registrars. That's not meaningful.


> See the comment from 'dsl upthread.

That comment has recieved appropriate and adequate rebuttals, so I see no need to add anything further.

> As for stats: https://dnssecmenot.fly.dev/

You said “Adoption of DNSSEC has barely budged”, and that is what the graph which I linked shows to be hilarously false. I remember that you often used to link the same graph – until it stopped showing what you wanted, that is. Now you come peddling a different, explicitly biased, graph, which only shows what the top 1% is doing, but I really don’t care about what the top %1:ers are doing. Most people are concerned with popularity in general, not what Google and Amazon are doing. Most people are not Google and Amazon, and consequently should take no lessons from them concerning their own systems.


You mean like this one? https://rick.eng.br/dnssecstat/

I cite the DNSSECMeNot thing now for two reasons:

(1) I wrote it.

(2) It's live: everything in the Tranco Top 1000 gets checked several times a day. I can tell you every site in that last that has changed DNSSEC status (turned it on or off) in the last year. Spoiler: you can count them on the fingers of two hands.

I don't know why you push on this statistics argument! It's really rough for you. If I was in your shoes I'd be trying to decrease their salience, not increase them.


> You mean like this one? https://rick.eng.br/dnssecstat/

What is this graph a reply to? Those graphs are for how many resolvers validating DNSSEC, not domains using DNSSEC. And here, your frequent pointing to Google and other large operators works against you, since all of them already validate DNSSEC!

Also, I find it highly questionable of you to link to a graph as part of an argument, without disclosing that you also made the software which makes the graph. (But the graph also wears its bias openly, so it’s at least honest about not being biased.)

> I don't know why you push on this statistics argument!

Notably, I did not bring it up. You brought it up, when you wrote “Adoption of DNSSEC has barely budged since [2015].” Which the graph from Verisign – which you also used to link to – shows to be utterly false.

The argument about DNSSEC with you always goes in circles. You claim that DNSSEC adoption is not rising. But the Verisign statistics show that more domains are DNSSEC signed than ever before, every day, both by numbers and percentage. Then you claim that the large masses of domains don’t count, but only the top 1% of 1% of popular domains, which are, notably, with some exceptions, not commonly DNSSEC signed. But those domains are used by Google and other infinitely large and alien actors, which have very different security models and threat models than most people with a domain name. Then you try to argue against the Verisign graph by posting a link to other graphs which claim to show “DNSSEC adoption”. But the graph you link to is not about domains, but about resolvers. However, the large and most popular resolvers are from Google, Cloudflare and the like, and all of those have done DNSSEC validation for a long time.


At this point I think if you want to keep talking you should just email me, because we're the only two people reading this. I don't understand either of your arguments here.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: