Every time someone tells me that DNSSEC tampering would be "detectible", it always seems premised on the idea that everyone sees the same data. Of course, attackers will isolate their targets and attack them surgically.
What's worse, none of what you're talking about is cryptographic. This is protection by dint of being lucky enough to be on the right part of the network to be hard to attack. No sound cryptosystem works like that.
The root zsk is split over a group (Shamir share) held by mostly non-US key holders. (One from the US is Dan Kaminsky, whose work and my user name has special relevancy for you. You'd agree he's not part of the US government.)
I believe all the key holders are trustworthy, and if any were not, you'd need a majority (5 of the 7) to subvert the zsk. So an xkcd-wrench-style attack on the key by governments would require implausible circumstances.
The key ceremony is video taped and can be watched:
https://www.youtube.com/watch?v=b9j-sfP9GUU
Other TLDs (some being countries) also hold key signing
ceremonies and video tape them. You can watch other
countries perform key signing as well. But these sovereign zsks are
subordinate to the ICANN community held keys.
I.e., it's more accurate (than your statement) to say that
there are seven people walking the earth who have
parent keys over actual country soveriegn zones. And while you
might not know all these people yourself, they're from the DNS
operator and hacker community. If anything, you're 180 degrees
wrong in your statement that governments run DNSSEC.You can read more about the DNSSEC root zone key management process and people (non-governmental) online. Here are informal press stories with the usual set of mistakes and minor errors:
http://www.theguardian.com/technology/2014/feb/28/seven-people-keys-worldwide-internet-security-web
https://www.schneier.com/blog/archives/2010/07/dnssec_root_key.html
And the root DNSSEC operation in general: http://www.root-dnssec.org/
I don't see the government in DNSSEC. Not even ICANN
can alter the root zsk (but they are of course instrumental
in any key roll over, since they manage the physical facilities
where the "DNSSEC Seven" must be iris scanned, etc., to sign
any proposed new root key).I think that reducing the amount of organizations controlling your particular branch of DNS is good. You may trust the US CA issue cert for US sites, those are more or less under their control anyway, but you probably don't want to trust them for .eu sites. Or why should I trust the Chinese CA for anything but chinese sites?
And more to the point: why should a CA be allowed to issue a cert for a site that already has a cert issues by another CA.
DNSSEC is hierarchic, there is one key for example.com. in the parent zone com., if someone else wants to put a key for example.com. into com. they'll have to replace it. Presumable the owner of example.com. would monitor its own record in com. and notice tampering. You can't easily have random CA issuing certs for your sites without being detected.
Of course having only a single entity is not good again, because then you introduce a single point of failure.
[*] well of course at the X509 level you have subordinate CAs, and a hierarchy, but it is in no way tied to DNS.
Sure, the root and major TLDs are anycasted across the globe, but the "wide range" of organizations are just mirroring content that is in one way or another controlled by world governments, and given (for example) ICE domain seizures, it would be prudent not to over-rely on DNS. Personally I support DNSCurve as a means to secure DNS, not to replace security we already have elsewhere.
Separately, DNScurve is interesting, but really solves a different problem than DNSSEC. I find this a useful comparison: http://security.stackexchange.com/questions/45770/if-dnssec-...
The private key of the DNS root was split in seven parts held by seven people [1]. It is stored in two HSMs, one on the east coast of the United States, one on the west coast. Could the NSA or some other agency have gotten hold of the private key? Probably. But spinning that as "the DNSSEC root is controlled by the governments" is FUD.
[1] http://venturebeat.com/2010/07/28/seven-security-experts-get...
If you do not trust the Lybian TLD, configure a negative trust anchor for that TLD in your resolver.
Alternatively, if you want to pin that TLD to a particular KSK, configure that KSK as a (positive) trust anchor in your resolver.
If you do not trust the IANA at all, disable the IANA root in your resolver and add trust anchors for the domains you trust. Use lookaside validation if you find that too cumbersome and want to let others do that work for you.
root@fw:~# unbound-host -t A -v bit.ly
bit.ly has address 69.58.188.39 (insecure)
bit.ly has address 69.58.188.40 (insecure)
More: http://dnssec-debugger.verisignlabs.com/bit.ly and http://dnsviz.net/d/bit.ly/dnssec/If those in charge of ly decided to implement dnssec, then who is in charge with respect to GP.
Because I'm trying to illustrate how much additional security you might or might not get if you added DNSSEC, especially with regards to government entities.
In order for this to be a useful exercise you should structure the question in such a way that there is as much potential for government interference as possible. (Unless you are looking for a specific answer and you are trying to lead the respondent.) Government interference with DNSSEC is not limited to the `.` zone. Or put another way, DNSSEC's attack surface area is not limited to the sacred KSK.
Here: .
Here: .ly.
Here: .bit.ly.
The attack surface of freebsd.org is similiar except there is a different set of actors that can exert legal influence over .org. Here: . # G/K/D same as bit.ly
Here: .org. # K/D same as bit.ly
Here: .freebsd.org. # K/D same as bit.ly