Dan York

Just a guy in Vermont trying to connect all the dots...

Author's posts

Over 75% of All Top-Level Domains (TLDs) Now Signed With DNSSEC (Featured Blog)

As I was entering in data for the weekly DNSSEC Deployment Maps, I was struck by the fact that we are now at the point where 617 of the 795 top-level domains (TLDs) are now signed with DNSSEC. You can see this easily at Rick Lamb's DNSSEC statistics site...Now, granted, most of that amazing growth in the chart is because all of the "new generic TLDs" (newgTLDs) are required to be signed with DNSSEC, but we are still seeing solid growth around the world. More...

FYI: Translated Pages To Start Appearing Soon On Deploy360 Site

List of six UN languagesAs Chris noted in his recent “Onwards and Upwards” post, one of our 2015 goals for this Deploy360 site is “to translate the most useful and often referenced resources into as many languages as is practical”.  As he went on to note, we’re currently in the process of translating some of those resources into the five languages other than English used by the United Nations.  Specifically:

  • Arabic
  • Chinese (Simplified)
  • French
  • Spanish
  • Russian

I have translations back from the firm we used and expect to be moving those into place over the next couple of weeks.  I wanted to give you all a heads-up about this since the website should show a translated version of the page when you get to a page if a translation is available… and so if you have your browser defaulting to a language other than English you may be surprised when you are visiting here!

Now, to set expectations, I should note that we translated the top 25 most visited resources on the site as well as the pages for each topic and the Start Here hierarchy of pages.  It’s not the whole site, but it’s a start.

I also wanted to post this because there may be a few bumps in the process and I don’t know if there will be impacts to the user experience of visiting this site.  If you do see pages loading strangely on the site, or experience issues with using the site, please be aware that it may be because I’m working on the site.  You are also welcome to report the issues to me.  I also anticipate a chance that some of the translated URLs could change as we experiment with the best way to make the information available.

Thanks for your patience and we look forward to being able to share our information with an even larger audience in more languages!

P.S. For those curious about how we are making translations of our pages available, we are using the WPML plugin for WordPress.

Over 75% of All Top-Level Domains (TLDs) Now Signed With DNSSEC (Featured Blog)

More...

Watch Live Today – DNSSEC Root KSK Ceremony 20 at 12:15 PST / 20:15 UTC

IANA logoStreaming live today from El Segundo, CA, will be the 20th “key ceremony” related to the Key Signing Key (KSK) for the Root zone of DNSSEC.  The page containing all the relevant links is at:

https://www.iana.org/dnssec/ceremonies/20

The ceremony starts at 12:15pm US Pacific Standard Time (20:15 UTC) and will conclude at 5:00 pm PST (01:00+1day UTC).  If you are interested in understanding more about the security of the overall DNSSEC system, the ceremony shows the process and care taken to administer the DNSSEC keys of the root of DNS.

The key ceremonies are part of the activities performed by the Internet Corporation for Assigned Names and Numbers (ICANN) under its contract to operate the Internet Assigned Numbers Authority (IANA). As explained on the overview page:

Ceremonies are usually conducted four times a year to perform operations using the Root Key Signing Key, and involving Trusted Community Representatives. In a typical ceremony, the KSK is used to sign a set of operational ZSKs that will be used for a three month period to sign the DNS root zone. Other operations that may occur during ceremonies include installing new cryptographic officers, replacing hardware, or generating or replacing a KSK.

This ceremony today is to use the “master” root Key Signing Key (KSK) to generate a set of Zone Signing Keys (ZSKs) that will then be used until the next key ceremony.

There is a lengthy script that outlines the process that will be used today:

http://data.iana.org/ksk-ceremony/20/KC20_Scripts.pdf

The process is open via the live video stream for all to see. The video recording will also be archived for later viewing.

P.S. If you want to learn more about how to get started with DNSSEC, please visit our “Start Here” page to find resources focused on your type of role or organization.

TDYR 215 – Reflections on Sri Lanka and the Road To Kandy

TDYR 215 - Reflections on Sri Lanka and the Road To Kandy by Dan York

FIR #791 – 1/19/15 – For Immediate Release

Eric Schwartzman joins FIR B2B; Marriott drops guest WiFi blocking effort; Quick News: Trade associations in DC spend more on PR than lobbying, Google Glass focus is business (not consumers), social media usage in 2014 and beyond, drones taking off as prices plummet; Ragan promo; News That Fits, LinkedIn and Facebook jokey for position in the enterprise, Dan York's Tech Report, WhatsApp sends 50% more messages than global SMS, Media Monitoring Minute from CustomScoop, listener comments, social grows up in B2b is one of five trends taking center stage this year, Igloo Software promo, the past week on the FIR Podcast Network, apps versus the mobile web; music from DownTown Mystic; and more.

FIR #791 – 1/19/15 – For Immediate Release

Eric Schwartzman joins FIR B2B; Marriott drops guest WiFi blocking effort; Quick News: Trade associations in DC spend more on PR than lobbying, Google Glass focus is business (not consumers), social media usage in 2014 and beyond, drones taking off as prices plummet; Ragan promo; News That Fits, LinkedIn and Facebook jokey for position in the enterprise, Dan York's Tech Report, WhatsApp sends 50% more messages than global SMS, Media Monitoring Minute from CustomScoop, listener comments, social grows up in B2b is one of five trends taking center stage this year, Igloo Software promo, the past week on the FIR Podcast Network, apps versus the mobile web; music from DownTown Mystic; and more.

TDYR 214 – Freitag in Frankfurt

TDYR 214 - Freitag in Frankfurt by Dan York

The Fundamental Tension Between Safety And Privacy (And The UK’s Proposed Encryption Ban)

How do we balance safety and privacy?  In a speech this week, UK Prime Minister David Cameron suggested that the UK ought to ban any communications applications that can't be intercepted - and said that if his government is re-elected this will be a major part of his legislation. His key question was:

"In our country, do we want to allow a means of communication between people, which even in extremis with a signed warrant from the home secretary personally, that we cannot read?"

Dan York

Over 600 Top-Level Domains Now Signed With DNSSEC

As I was entering in data for the weekly DNSSEC Deployment Maps, I was struck by the fact that we are now at the point where 615 of the 793 top-level domains (TLDs) are now signed with DNSSEC. You can see this easily at Rick Lamb’s DNSSEC statistics site:

DNSSEC statistics

This represents 77% of all current TLDs!

Now, granted, most of that amazing growth in the chart is because all of the “new generic TLDs” (newgTLDs) are required to be signed with DNSSEC, but we are still seeing solid growth around the world.  If you look at the most recent DNSSEC Deployment Maps you can see that much of the world is being shown as “green” as more and more country-code Top Level Domains (ccTLDs) sign with DNSSEC:

ccTLD dnssec deployment map

Of course, having a TLD signed doesn’t mean that the second-level domains will be signed with DNSSEC. As various DNSSEC statistics sites will show, the percentage of signed second-level domains varies widely, from around 80% in .GOV down to tiny percentages in other TLDs.

BUT… the key point is that the first step in signing your domain is to be sure that your TLD is signed!

After the TLD has been signed, THEN steps can be taken to get more DNSSEC deployment happening underneath that TLD.  Look at how successful Norway has been with .NO after they recently signed the domain!

With some of the work that is happening via various DNSSEC Workshops,  ICANN’s DNSSEC training and other forums I know that we’ll see more and more of the TLDs being signed in the months ahead.  The excuse that “TLDs are not signed with DNSSEC” can no longer be used as an excuse for NOT working with DNSSEC and DANE!

Great to see!

P.S. If you want to get started with DNSSEC, please visit our Start Here page to find resources to help you begin.