<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[I felt a great disturbance in the Force, as if millions of domains suddenly cried out in terror and were suddenly silenced.]]></title><description><![CDATA[<p>I felt a great disturbance in the Force, as if millions of domains suddenly cried out in terror and were suddenly silenced.</p><p>The .de TLD is the third largest in the world with ~18 million domains. All DNSSEC-aware resolvers didn’t serve any of those. </p><p>We just cancelled the Major Incident and sent everyone to bed. The remaining impact is outside our sphere of influence.</p><p><a href="https://infosec.exchange/tags/dns" rel="tag">#<span>dns</span></a> <a href="https://infosec.exchange/tags/dnssec" rel="tag">#<span>dnssec</span></a> <a href="https://infosec.exchange/tags/denic" rel="tag">#<span>denic</span></a></p>

<div class="row mt-3"><div class="col-12 mt-3"><img class="img-thumbnail" src="https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/524/352/122/337/636/original/59a473f8409e4ecb.jpeg" alt="Link Preview Image" /></div></div>]]></description><link>https://board.circlewithadot.net/topic/721f9527-0ac7-4b18-80e2-56483f347e35/i-felt-a-great-disturbance-in-the-force-as-if-millions-of-domains-suddenly-cried-out-in-terror-and-were-suddenly-silenced.</link><generator>RSS for Node</generator><lastBuildDate>Thu, 14 May 2026 23:35:40 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/721f9527-0ac7-4b18-80e2-56483f347e35.rss" rel="self" type="application/rss+xml"/><pubDate>Tue, 05 May 2026 22:38:56 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to I felt a great disturbance in the Force, as if millions of domains suddenly cried out in terror and were suddenly silenced. on Wed, 06 May 2026 06:16:41 GMT]]></title><description><![CDATA[<p><span><a href="/user/karlauerbach%40sfba.social" rel="nofollow noopener">@<span>karlauerbach</span></a></span> There are some very German points to this. The operational instance belongs de facto to domain traders. </p><p>I will push for more information.</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/masek/statuses/116526166944796492</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/masek/statuses/116526166944796492</guid><dc:creator><![CDATA[masek@infosec.exchange]]></dc:creator><pubDate>Wed, 06 May 2026 06:16:41 GMT</pubDate></item><item><title><![CDATA[Reply to I felt a great disturbance in the Force, as if millions of domains suddenly cried out in terror and were suddenly silenced. on Wed, 06 May 2026 05:57:50 GMT]]></title><description><![CDATA[<p><span><a href="/user/masek%40infosec.exchange">@<span>masek</span></a></span> That sounds crazy.  DNSSEC is a sequence of keys in a hierarchy that starts at the root (or a trust anchor) and works down through the zones.  One can't validate a record without that full sequence of keys.</p><p>As long as 20+ years ago when DNSSEC was a baby and I was arguing for competing roots one of the questions was whether DNSSEC tied the name hierarchy to exactly one root zone file - the answer is "yes, sort of" - and whether competing roots could use that with a different set of root NS records in that file - the answer is "yes".</p><p>I was always concerned about the key management - often the most complicated part of any crypto system - and I had faith in people like Patrick F. to figure it out (they did.)</p><p>I thought that ICANN and the ORSC had gone over and carefully rehearsed key updates and roll over procedures.</p><p>I was just, this week, discussing with ICANN folk about my 20 year old idea of establishing a worldwide DNS early warning system.</p>]]></description><link>https://board.circlewithadot.net/post/https://sfba.social/users/karlauerbach/statuses/116526092845340296</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://sfba.social/users/karlauerbach/statuses/116526092845340296</guid><dc:creator><![CDATA[karlauerbach@sfba.social]]></dc:creator><pubDate>Wed, 06 May 2026 05:57:50 GMT</pubDate></item><item><title><![CDATA[Reply to I felt a great disturbance in the Force, as if millions of domains suddenly cried out in terror and were suddenly silenced. on Wed, 06 May 2026 05:19:38 GMT]]></title><description><![CDATA[<p><span><a href="/user/karlauerbach%40sfba.social" rel="nofollow noopener">@<span>karlauerbach</span></a></span> Technically it was quite simple: they suddenly used a new ZSK (zone signing key) nobody else (especially the root NS) knew nothing about and killed the trust chain.</p><p>Every DNSSEC aware resolver refused to resolve any .de domain.</p><p>Workaround was that a hell lot of ISPs disabled DNSSEC on their resolvers.</p><p>They needed 150min to fix that problem (revert to the old ZSK), they didn't say a word about the cause yet.</p><p>An utter and complete shitshow.</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/masek/statuses/116525942618293309</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/masek/statuses/116525942618293309</guid><dc:creator><![CDATA[masek@infosec.exchange]]></dc:creator><pubDate>Wed, 06 May 2026 05:19:38 GMT</pubDate></item><item><title><![CDATA[Reply to I felt a great disturbance in the Force, as if millions of domains suddenly cried out in terror and were suddenly silenced. on Wed, 06 May 2026 05:01:46 GMT]]></title><description><![CDATA[<p><span><a href="/user/karlauerbach%40sfba.social" rel="nofollow noopener">@<span>karlauerbach</span></a></span> I will send an update later today. There is no word about the root cause yet. I am deeply disturbed.</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/masek/statuses/116525872322016040</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/masek/statuses/116525872322016040</guid><dc:creator><![CDATA[masek@infosec.exchange]]></dc:creator><pubDate>Wed, 06 May 2026 05:01:46 GMT</pubDate></item><item><title><![CDATA[Reply to I felt a great disturbance in the Force, as if millions of domains suddenly cried out in terror and were suddenly silenced. on Wed, 06 May 2026 04:53:01 GMT]]></title><description><![CDATA[<p>I am still speechless about the incident. That is something that should have been impossible to happen at that level.</p><p>Personally, I really felt a disturbance in the force.</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/masek/statuses/116525837948686069</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/masek/statuses/116525837948686069</guid><dc:creator><![CDATA[masek@infosec.exchange]]></dc:creator><pubDate>Wed, 06 May 2026 04:53:01 GMT</pubDate></item><item><title><![CDATA[Reply to I felt a great disturbance in the Force, as if millions of domains suddenly cried out in terror and were suddenly silenced. on Tue, 05 May 2026 23:56:16 GMT]]></title><description><![CDATA[<p><span><a href="/user/masek%40infosec.exchange">@<span>masek</span></a></span> Details?</p><p>Were these DNSSEC aware resolvers returning no-such domain responses?</p><p>Was there an error in the signing?</p><p>What tools are proving useful in understanding and diagnosing the issue?</p>]]></description><link>https://board.circlewithadot.net/post/https://sfba.social/users/karlauerbach/statuses/116524671082473645</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://sfba.social/users/karlauerbach/statuses/116524671082473645</guid><dc:creator><![CDATA[karlauerbach@sfba.social]]></dc:creator><pubDate>Tue, 05 May 2026 23:56:16 GMT</pubDate></item><item><title><![CDATA[Reply to I felt a great disturbance in the Force, as if millions of domains suddenly cried out in terror and were suddenly silenced. on Tue, 05 May 2026 23:33:39 GMT]]></title><description><![CDATA[<p><span><a href="/user/masek%40infosec.exchange">@<span>masek</span></a></span> </p><p>If only DNS was decentraiised</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/SpaceLifeForm/statuses/116524582170388660</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/SpaceLifeForm/statuses/116524582170388660</guid><dc:creator><![CDATA[spacelifeform@infosec.exchange]]></dc:creator><pubDate>Tue, 05 May 2026 23:33:39 GMT</pubDate></item></channel></rss>