logoalt Hacker News

baggy_troughtoday at 4:42 PM2 repliesview on HN

I'm too afraid to turn it on.


Replies

tptacektoday at 4:48 PM

Really? You're not concerned that someone might do a very specific kind of on-path DNS cache corruption attack, in 4-5 places simultaneously around the world to defeat multipath lookups at CAs, in order to misissue a certificate for your domain, which they can then leverage in MITM attacks they're somehow able to launch to get random people to think they're looking at your website when they're looking at something else? And that risk doesn't outweigh the fairly strong likelihood that at some point after you enable DNSSEC something will happen to break that configuration and make your entire domain fall off the Internet for several days?

show 3 replies
Joel_Mckaytoday at 6:02 PM

If you handle minimal traffic loads it should be fine.

On a busy site, the incurred additional load cost can bite hard.

A lot of people will leave it off for the same reasons as DoH or DoT. =3