Rolling the Root Key

(blog.apnic.net)

21 points | by speckx 2 days ago

3 comments

  • ttul 2 hours ago
    Dan Kaminsky told me about the signing ceremony years ago (bless his heart, he was one of the people trusted with DNS security). Apparently, everyone on the signing committee flies to a central location carrying a hardware key. Then they take turns inserting their hardware key into a hardware security module. It's all done face-to-face because that's the only way to guarantee that human consent was granted properly at each step.

    Each ceremony is recorded on video and distributed to the public. The last one was in August, 2026: https://www.youtube.com/watch?v=-QqYS3oLfL8&t=1s

    • tptacek 2 hours ago
      The whole thing is performative (it's why the people with the key shares had them: to generate publicity for DNSSEC). The root keys could wind up on Pastebin tonight and almost nobody in the world would need to be paged.
      • zamadatix 1 hour ago
        The great thing about DNSSEC is only those who care need care, those who don't seem to need to let everyone on HN know that's the case.
        • tptacek 1 hour ago
          This kind of thing makes sense when DNSSEC is brought up incidentally somewhere, but makes a lot less sense when we're discussing the solemnity and gravity of the DNSSEC key signing ceremonies, for which it is actually useful context to know that they are entirely performative.

          Really the only important thing to know about DNSSEC root key rollovers is that this is only the second one they've ever done, and the last one was kind of a fiasco --- they had to delay it an entire year for logistical reasons.

      • alfons_foobar 1 hour ago
        You mean because the majority of the DNS is still unsigned?
        • tptacek 37 minutes ago
          Yes, that, but also: virtually nobody has any actual security depending on DNSSEC at this point. DNSSEC isn't load-bearing, as it were. We had a DNSSEC-related outage in Germany a few months ago, and major providers (including all of Cloudflare) responded to it by disabling DNSSEC, which is something you don't do with security infrastructure.

          I'm not being hyperbolic when I say the DNSSEC root keys could --- literally --- show up on Pastebin tonight and almost nobody would need to be paged.

      • teddyh 2 hours ago
        [flagged]
    • paaloeye 2 hours ago
      Excellent Waveform podcast explaining it for general public: https://www.youtube.com/watch?v=26WvISI14g0
  • paaloeye 3 hours ago
    I'm requesting David's, Ellis's, and Adam's from Waveform: MKBHD Podcast attendance.

    Context: https://www.youtube.com/watch?v=26WvISI14g0