for d in Amazon.com Facebook.com Apple.com Google.com Netflix.com ; do delv "$d" @1.1.1.1; done for d in Amazon.com Facebook.com Apple.com Google.com Netflix.com ; do delv "$d" @1.1.1.1; done1. The overwhelming majority of those names are meaningless, just as it doesn't change anything about Internet security if I do or don't sign the "paulgra-ham.com" domain I bought on Hover years ago when I was drunk.
2. Registrar signatures are more or less security theater, because those customers aren't even controlling their own keys.
The total adoption of DNSSEC in commercial zones is between 1-4% right now, right?
> 2. Registrar signatures are more or less security theater, because those customers aren't even controlling their own keys.
It would be nifty if DNSSEC (or some superior technology) provided a degree of protection against a compromised registrar, but I don’t think that’s the primary benefit. Of course the registrar can change the DNS data.
DNSSEC purports to secure the transfer of data from the combination of the registrar and the domain owner to the resolver. For example, the combination of DNSSEC and CAA can, in principle, prevent even an arbitrarily privileged attacker on the network from getting a bogus certificate issued. Without DNSSEC, services like Let’s Encrypt rely on a degree or network voodoo to protect against MITM attack.
(Of course, a much simpler and more robust mechanism could accomplish the same goal. For example, there could be a standardized out of band mechanism by which a CA could securely ask a registry for the certificate policy for a domain. Something like this wouldn’t have the admin-screwed-up—and-the-whole-domain-is-down failure modes.)
edit: It looks like RDAP is moderately close to being able to do that out-of-band verification. I wonder if anyone is working on CAA integration with RDAP.