Web PKI: How to protect a popular security service?
Guest Post: Lessons learned from a study on the interrelation of CAA, CT, and DANE in web PKI deployments.
Guest Post: Lessons learned from a study on the interrelation of CAA, CT, and DANE in web PKI deployments.
Investigating the EDNS0 option for DNS, focusing on the specified maximum UDP packet size and its practical implications in the modern Internet.
Following on from his last podcast, Geoff explores how to fix the problem in DNSSEC deployment and how this can benefit TLS.
If quantum computing becomes viable, Post Quantum Cryptography (PQC) will be needed to replace RSA and ECC signatures in DNSSEC. How well can today’s DNS system handle PQC methods?
Guest Post: What lessons can we learn from the development of DNSSEC?
The DNS has evolved significantly during the Internet’s lifetime. What’s changed and what’s remained the same?
Geoff Huston discusses the market failure of DNSSEC in deployment.
DNSSEC bootstrapping, DELEG update, DNS energy consumption, resolver BCP, and more from RIPE 88.
Should we drop DNSSEC and just move on?
Just how ‘devastating’ is the Keytrap vulnerability? How it works, and what the response has been.