That doesn't seem right. Ever since enabling DNSSEC validation on my system, YouTube and every other Google product except basic searching is broken for me. The percentage of internet users who enforce DNSSEC must be much much smaller.
That doesn't seem right. Ever since enabling DNSSEC validation on my system, YouTube and every other Google product except basic searching is broken for me. The percentage of internet users who enforce DNSSEC must be much much smaller.
So I can absolutely see where this would easily be the case, if not more.
You can view a map of DNSSEC validation rates here: https://stats.labs.apnic.net/dnssec
Enabling DNSSEC wouldn't change resolution of those properties unless you somehow set your system to treat insecure delegations as bogus. Is that what you've done?
Of course there's not much point to that evaluation if you're only looking up IP addresses and then relying on WebPKI to see that the other end is what you expected it to be.
EDIT:
I'm not allowed to reply for some reason, so in answer to tptacek:
> Right, which leaves open the question of what the point is.
No, I don't think it does. I think my summary reasonably conveys the functionality DNSSEC offers and how it is practically useful. (This is not a flippant response, the spade is a spade.)
A more pointed critique implied by the thread you're replying to is: if virtually nothing on the Internet is signed, what's the point?
The ATHENE team's Black Hat talk from last year surveyed the "Tranco Top 500k", whatever that is, but I'll just say that 500k is more hosts than the 500 top hosts I use from the Moz500 for the same stat, and found that (wait for it) less than 5% of hosts in that dataset worldwide were signed, and a substantial number of those hosts are just signed by their registrars.
If you were going to make a case for an ordinary Internet user, like, the modal American user, to enable DNSSEC --- what would it be? What benefit would they get?
The argument that absolutely nothing that the world relies on, is not being singed (google Facebook reddit Cisco MicroSoft etc) holds no clout with the believers, unfortunately.
Google doesn't use DNSSEC, unfortunately, so this shouldn't be a problem. If your resolver breaks on this, I think that may be the result of a bug or misconfiguration, because there's no DNSSEC to validate here.
That number does still seem high though.
Consulting and working for MSPs over the last 10 years I've probably been exposed to a couple hundred environments and I've never once seen DNSSEC validation used.