I hope the situation gets resolved swiftly, and lessons learned from this incident can contribute to stronger and more reliable DNSSEC practices in the future.
The root KSK rollover had to be postponed twice, for several years, because of operational problems pulling this off in the US. It's difficult to do because the nature of the DNS makes it difficult. The utility of DNSSEC is so marginal that it's kind of sad that you're right, and that engineers are gradually getting better doing this hard, stupid thing.
You're not learning if you're not failing, so failing is good actually.
I think the pithy saying is that we learn best from failure, not that there is no other way to learn.
Yep: "don't deploy DNSSEC, rely on TLS"
TLS security is rooted in DNS. It's ACME DNS-01. If your threat model includes nation states, this is a non-solution
Wrong, TLS security is independent from DNS. If my threat model includes nation states I'll trust my own certificates or my very own CA.
By trusting certificates, you implicitly trust all CAs, not just your own.
You trust your browser's root program, not "all CAs".
That’s what a “CA” is. If someone is not in a browser’s CA list, they’re not a CA. So yes, you do trust all CAs.
That’s not all what CA means in standard usage. Terms like WebPKI exist specifically to make that distinction since, for example, the U.S. government runs its own certificate authorities which are trusted by millions of clients and even some mainstream software (Adobe) but not browsers. This is far from unique as far as governments go, and in some cases may even be required within a country.
Those non-web CAs are not the topic of discussion, though. When we are discussing the DNSSEC PKI, we are not discussing any altroots¹. When people are discussing the CA system for TLS, they overwhelmingly mean the normal web CAs.
"The normal web CAs" means "the Mozilla and Chrome root programs". There are other CAs, and some of them are even in the root stores of other browsers, but they're not "trusted" in the sense you meant upthread.
No, obviously, different TLS programs have different root programs.
No, again in that threat model I can decide exactly which certificates and which CA I trust, one by one.
If your threat includes nation states then DNSSEC is double-useless?
If your threat model includes nation-states then DNSSEC won't help you either. WebPKI at least has a method for keeping track of and detecting misissuance, DNSSEC doesn't.