You could just as well say that political protest is not a thing, that it’s just vandals looking for reasons to break stuff.
26,870 karma · joined July 11, 2013
pub 4096R/DE0572E4 2014-12-07
Key fingerprint = 63BE 5B92 CFE0 4185 6195 9459 EB9B 1B01 DE05 72E4You could just as well say that political protest is not a thing, that it’s just vandals looking for reasons to break stuff.
It actually happened in 2016: <https://news.ycombinator.com/item?id=21092184>, so no ”coincidence”.
Which is wrong. He does not. You yourself cite him, at length, where he explains why he does not support it.
Oh, well, time to link stuff again, I guess:
Or a dog: <https://en.wikipedia.org/w/index.php?title=Roundabout_dog&ol...>
My arguments can be summarizes as follows: 1. The usage of DNSSEC is, contrary to your claim, going up, steadily. By number of domains signed, percentage of domains signed, and usage of DNSSEC-verifying resolvers. 2. Your argument seems to be that a) The increasing number and ratio of DNSSEC signed domains do not count, only big-name domains like Google are important (since many of those are still not DNSSEC signed), but b) big-name resolvers like Google are simultaneously not important, since those all do verify DNSSEC signatures. This argument is inconsistent. 3. Linking to, and trying to prove an argument by, your own biased graph using your own software, without disclosing that it is your graph and software, is scummy.
I suspect that SEO measurement has told people that it doesn’t matter what images an article has, as long as it has some images, optimally interspersed with the text. Spending any money on getting relevant images thus becomes an unnecessary expense. Readers will still click on the article (because of the click-bait headline), and will still read (or at least scroll through) the article if the text is broken up by images by an optimal amount.
(Repost from three years ago: <https://news.ycombinator.com/item?id=37167492>)
What is this graph a reply to? Those graphs are for how many resolvers validating DNSSEC, not domains using DNSSEC. And here, your frequent pointing to Google and other large operators works against you, since all of them already validate DNSSEC!
Also, I find it highly questionable of you to link to a graph as part of an argument, without disclosing that you also made the software which makes the graph. (But the graph also wears its bias openly, so it’s at least honest about not being biased.)
> I don't know why you push on this statistics argument!
Notably, I did not bring it up. You brought it up, when you wrote “Adoption of DNSSEC has barely budged since [2015].” Which the graph from Verisign – which you also used to link to – shows to be utterly false.
The argument about DNSSEC with you always goes in circles. You claim that DNSSEC adoption is not rising. But the Verisign statistics show that more domains are DNSSEC signed than ever before, every day, both by numbers and percentage. Then you claim that the large masses of domains don’t count, but only the top 1% of 1% of popular domains, which are, notably, with some exceptions, not commonly DNSSEC signed. But those domains are used by Google and other infinitely large and alien actors, which have very different security models and threat models than most people with a domain name. Then you try to argue against the Verisign graph by posting a link to other graphs which claim to show “DNSSEC adoption”. But the graph you link to is not about domains, but about resolvers. However, the large and most popular resolvers are from Google, Cloudflare and the like, and all of those have done DNSSEC validation for a long time.
That comment has recieved appropriate and adequate rebuttals, so I see no need to add anything further.
> As for stats: https://dnssecmenot.fly.dev/
You said “Adoption of DNSSEC has barely budged”, and that is what the graph which I linked shows to be hilarously false. I remember that you often used to link the same graph – until it stopped showing what you wanted, that is. Now you come peddling a different, explicitly biased, graph, which only shows what the top 1% is doing, but I really don’t care about what the top %1:ers are doing. Most people are concerned with popularity in general, not what Google and Amazon are doing. Most people are not Google and Amazon, and consequently should take no lessons from them concerning their own systems.
Which of the rebuttals in the link I gave don’t stand?
> Adoption of DNSSEC has barely budged since I wrote it.
According to this graph, DNSSEC adoption seems to now be roughly 16×, i.e. 1600%, of what it was when you wrote it:
https://www.verisign.com/resources/dnssec-tools/dnssec-score...
Yes; here is one instance: <https://www.youtube.com/watch?v=n45D_zi3O5g#t=14m13s>
”DNS security” can mean many things, but DNSSEC was meant to solve the problem of verification of DNS data, while still allowing for offline signing and secondary DNS servers serving pre-signed zones, without distributing the key everywhere. DoH/DoT do not solve this; they solve different problems.
From: hermann@cpsc.ucalgary.ca (Michael Hermann)
Subject: Programmming awards
Date: 10 Feb 89
At Calgary, the computer science department has an award called
the Williams Cup (as in old stained coffee cup), which is given
yearly to the student who hands in the most imaginative
rendition of a regular programming assignment. Anyway, as the
story goes, the cup was awarded to a student who'd done a desk
calculator assignment. Seems that the prof hadn't specified
that you had to do it in decimal, so his/her program did math
with _roman_numerals_.
The clincher for the award must have been his/her programming
style, since of course, the documentation was in _latin_.
— <https://www.cs.earlham.edu/~skylar/humor/Unix/computer.folkl...>