Just a guy in Vermont trying to connect all the dots...
Author's posts
Aug 06
Why Is Skype Forcing A Software Upgrade On All Of Us? (Plus The Community Outrage)
Today when I opened up my laptop and switched to Skype, I found that I had been logged out:
The text in that image says:
We've signed you out because you're using an outdated version of Skype. Download the latest version now.
Now, to be clear, I wasn't using an ancient version of Skype. My laptop had version 6.3.0.602 from sometime in, say, March 2013 - so yes, it was over a year old, but the thing with Skype is that it has had a history of always "just working", which perhaps we as users have gotten used to. The upgrade went fine on my MacBook Pro that is still running Mountain Lion (10.8) and I'm now using Skype version "6.15 (334)".
Community Outrage
In a Skype public chat in which I participate a number of other users said they'd been logged out - and looking in the Windows Skype community and Mac Skype community web forums I see MANY messages from people who are experiencing problems over the past week. The frustration is even visible in the Linux Skype community (a community Skype has often ignored), where a staff moderator posted last Friday, August 1, this message:
From today, users with Skype for Linux version 4.2 and older will not be able to sign in to Skype. The error messages user will see during sign in may include “Can’t Connect to Skype” or ”Can’t login on Skype”. To continue using Skype, please update to the latest version.
The replies mostly indicate that the "new" version of Skype won't work on various configurations of Linux. The 99th response to the threadperhaps sums up the anger best:
In all your web content you people claim that forcing us to drop 4.2 and move to 4.3 improves our lives and makes our Skype experience better. If you have bothered to read all the responses in this topic, by now I hope you understand: YOU ARE NOT MAKING SKYPE BETTER FOR US. 4.3 breaks audio compatibility. Pulseaudio does not work with my USB external audio equipment, and running it causes my other audio-based apps to stop working. If you want to make Skype better for us, put ALSA support back in. Or release the source code so we can do it ourselves. Or stop blocking 4.2 so we can continue using the version that DOES make our lives easier. What you have done to Skype is an abomination.
You can see similar sentiment in the lengthy thread in the Mac community. Here's the 78th message in the thread:
Hello. Okay, straight to the point. THIS is not a solution. I've tried many times diferent ''approaches'' to this problem. From trying to use an old version 2.8 to just plainly updating in the skype app as asked (which I downloaded and when I tried to sign in it logs me out cuz its asks AGAIN for the update); I even tried unistall skype and download it again, but everything fails. And no, I won't update to Mavricks; I'm fine with the current version I have; thanks. So, plz, I do like skype, its awesome for work (which I use EVERYDAY) and keep in contact, but this is waaaaaaay out. PLEASE GIVE A SOLUTION. THANK YOU. :happy:
A big issue in reading the threads seems to be that many people still need to use older versions of their base operating system - and the latest versions of Skype will not work with those operating systems. Here's an example:
I'm ready to drop Skype. I do not allow even APPLE to tell me how to configure my computer, much less MICROSOFT (who owns skype since 2011). There is no way I'm upgrading to Mavericks. Absolutely no need, and I still use applications that require Rosetta, which is not available in anything past 10.6.8.
Bye bye skype. I'll use it on my iPhone, but no more on my desktop, and if it gets weird on my iPhone skype will simply lose a customer. Period.
There are MANY more examples... and many more in the Windows community as well. All in all it seems that this "forced upgrade" is not going down well with many people.
Skype's Statements
As far as I can see, Skype is pointing people to this support article about upgrading that says:
We want everyone to experience the best Skype has to offer – from enhanced quality to better reliability to improved security – and the newest version of Skype is the way to do that. So everyone can benefit from the latest improvements, from time to time we retire older versions of Skype across all platforms, including mobile devices. It’s easy to update Skype; once you do, you’ll have access to the latest features our team has worked hard to deliver.When we retire older versions of Skype, if you are still on an older version, you would be signed out of Skype automatically and won’t be able to sign in again until you upgrade to a new version. Simply follow the steps below to download, install, and sign in to the latest version, and you’ll be back in Skype in no time.
Skype also provided a bit of a preview of this action in a July 16, 2014, blog post titled "Update Skype now to improve your experience" where they trumpted all the benefits of upgrading and included one little line about the impending retirement:
So everyone can benefit from the latest improvements, we’ll retire older versions of Skype across all platforms, including mobile devices, in the near future.
where it turns out that "in the near future" meant about two weeks later at the end of July 2014. :-(
But Why, Skype?
The lingering question is... why now?
I mean, I do understand that one of the strengths of Skype historically has been that it "just worked" and that pretty much any version of Skype would still let you connect. This has allowed Skype to become the amazingly ubiquitous communication tool that it has become.
The down side of this for Microsoft/Skype is that they can't get people to use all their new services - or see their new ads - if there are so many older versions.
Similarly, they can't move to new technical architectures that may provide better service when they have to also support a long history of past releases. (For example, their move away from the peer-to-peer architecture that was their original highlight to more of a centralized "cloud" architecture to provide better support for mobile clients.)
I get all that.
I can understand why Microsoft would want - even need - everyone to use newer versions of Skype.
But why now? Why the end-of-July 2014 point? Was that just an arbitrary date? Is there something else driving it?
And what changes are being made in these newer versions? Is it, as one friend said, because Microsoft wants to move away from P2P chat? Or make some other technical changes?
What are they doing that caused them to decide NOW was the time to move?
The somewhat crazy thing with the timing is that it is not like Skype is the only choice for people now. There are a ton of competing communication channels. I've personally been using Apple's Facetime and Google+ Hangouts a good bit more these days for communication. As I wrote about recently, Facebook is clearly looking to make their Messenger be a mobile tool for voice and chat communication. And there are many other mobile apps that are trying to be "the next Skype". Plus... there is the whole world of WebRTC and the zillion new apps and sites that are providing new ways to communicate.
And maybe THAT is the driver. Perhaps Microsoft realizes that to compete with all these new services and to be able to evolve Skype they NEED to force users to come up to the latest versions. Perhaps they are hoping that any disruption in users behavior will be only temporary and that after that migration they can then move ahead faster.
Or perhaps this is just part of the general changes that Microsoft is making to re-focus their energy and staff. As shown by their recent large round of layoffs, the way they have been doing things hasn't been working - and they need to change. Perhaps they view the customer hostility (and potential switching) that will come from forcing these upgrades will be balanced out by their lower support costs by not having to support older models.
Or perhaps they just think of us all as sheep who won't be bothered to change.
I don't know. And Skype doesn't seem to be saying beyond their vague platitudes about how upgrading will benefit everyone.
Will Users Move To Alternatives?
The question is, of course, will users actually move to alternatives?
Judging by the outrage in many of those community forums it appears that Microsoft may have underestimated the technical problems that users would face with these upgrades. I see a lot of people saying they can't upgrade to Skype due to their operating system version or other issues.
Skype is effectively dead to them.
So in this case they will have to find an alternative because they simply can't use Skype.
But there is no easy way to know what percentage of people are affected by these upgrade issues. It could be quite small. It could be that the vast majority of users have automatically updated with no problem.
I took a look at Hudson Barton's Skype user statistics but unfortunately his system stopped collecting statistics on July 31st . He's restarted it now... but the data has been lost for this past week that might have shown us what, if any, impact there was. He is showing 77 million Skype users online right as I write this, which is consistent with recent numbers.
It's also not clear where Microsoft/Skype is in rolling out this forced upgrade to their users. From the user community posts it seems many people started experiencing this problem back on July 30th or 31st. I just received the notification this morning, August 6th. I know from others online that they are still using older versions and have not yet received the forced upgrade notice.
We've been here before, too. Back in December 2010 there was a Skype outage that disconnected almost everyone for several days. Many of us thought this might provide a push to people to try another service... and it didn't. Once the outage was over people generally went back to using Skype. It was easy - and the directory is there, i.e. so many people you know use Skype that it makes it super easy to connect with people that way.
Times are different in 2014, though. There are more and better choices than there were four years ago. Offerings from Apple, Google and Facebook all are quite compelling - and bring with them a directory of users. Perhaps not as many as on Skype, but still quite solid.
What will you do?
Switch to using more of another service such as iMessage, Google+ Hangouts or Facebook? Try out a startup such as Tox?[1] Use one of the many mobile apps?
Or will you just stick with Skype? (Assuming, of course, that you can upgrade.)
[1] Naturally I'm trying out Tox, but that's just because I'm always trying out new services... and hey, how can I not try out a service that encourages people to use IPv6? :-) (And if you want to try connecting to me there, my Tox ID is the incredibly hard to relay string of B1B85CBFB6DFBC72729F8D6113A626B116317A224C09A50BFB9C5ABDCCE5187A13701016DE8A ... I think they need to work a bit on the user experience for this to really be useful!)
If you found this post interesting or useful, please consider either:
- following me on Twitter;
- adding me to a circle on Google+;
- following me on App.net
- subscribing to my email newsletter; or
- subscribing to the RSS feed
Aug 06
WebRTC “Just Works” Over IPv6…
I love opening up my computer in the morning and seeing tweets like this one:
I've tested #WebRTC with Chrome talking to a ICE-Lite WebRTC server on IPv6. It just works. Nice.
— Iñaki Baz Castillo (@ibc_tw) August 6, 2014
The text is:
I’ve tested #WebRTC with Chrome talking to a ICE-Lite WebRTC server on IPv6. It just works. Nice.
And THAT is the way it should be. For all the work we do as a community and industry to advance the deployment of IPv6, in the end the user experience should be exactly that… it should “just work”. Users shouldn’t notice – or care – that their traffic goes over IPv4 or IPv6.
Kudos to the Chrome team for making it so that WebRTC “just worked” over IPv6. And kudos to Iñaki Baz Castillo for noticing!
Now, let’s get out there and make everything else “just work” over IPv6! 🙂
If you’d like to get started with making your applications or network work with IPv6, please check out our “Start Here” page to find resources tailored to your type of role and organization – and please let us know if you need more information.
UPDATE: A bit more information about what made the WebRTC application “just work” in Chrome. Per Iñaki Baz Castillo, he had this bit of JavaScript code in the WebRTC app that the browser downloaded:
var pc_constraints = {
mandatory: { googIPv6: true }
};
That bit of code made his app work over IPv6.
The post WebRTC “Just Works” Over IPv6… appeared first on Internet Society.
Aug 06
WebRTC “Just Works” Over IPv6…
I love opening up my computer in the morning and seeing tweets like this one:
I've tested #WebRTC with Chrome talking to a ICE-Lite WebRTC server on IPv6. It just works. Nice.
— Iñaki Baz Castillo (@ibc_tw) August 6, 2014
The text is:
I’ve tested #WebRTC with Chrome talking to a ICE-Lite WebRTC server on IPv6. It just works. Nice.
And THAT is the way it should be. For all the work we do as a community and industry to advance the deployment of IPv6, in the end the user experience should be exactly that… it should “just work”. Users shouldn’t notice – or care – that their traffic goes over IPv4 or IPv6.
Kudos to the Chrome team for making it so that WebRTC “just worked” over IPv6. And kudos to Iñaki Baz Castillo for noticing!
Now, let’s get out there and make everything else “just work” over IPv6!
If you’d like to get started with making your applications or network work with IPv6, please check out our “Start Here” page to find resources tailored to your type of role and organization – and please let us know if you need more information.
UPDATE: A bit more information about what made the WebRTC application “just work” in Chrome. Per Iñaki Baz Castillo, he had this bit of JavaScript code in the WebRTC app that the browser downloaded:
var pc_constraints = {
mandatory: { googIPv6: true }
};
That bit of code made his app work over IPv6.
Aug 05
Administrative Update: Web site migration completed, mailing list still to do
As we mentioned previously, the DNSSEC Deployment Initiative website and mailing list are in the process of being moved to hardware running on the Internet Society’s infrastructure. The migration of the web site has now been completed. To be sure you are seeing the new site, you should now see a “Deploy360″ logo in the right navigation bar. If you don’t, you are still seeing the old site, but should see the new site soon.
You can also now comment without logging into the site. We’ll be making a number of other smaller back-end changes to the site… but you shouldn’t notice any of those.
If you do see anything strange happening with the website, please email me at york@isoc.org.
The dnssec-deployment@dnssec-deployment.org mailing list still needs to be moved to ISOC’s infrastructure. That change will be happening sometime in the next few weeks.
Aug 05
InfoWorld: Why You Need To Deploy DNSSEC Now
Today long-time DNS expert Cricket Liu came out with a good post on InfoWorld, “Why you need to deploy DNSSec now ” where he talks through
- why you need DNSSEC
- how it works, including a walk-through of the actual RRSIG record in DNS
- human factors that delayed implementation
- motivation for deploying DNSSEC (or lack thereof)
- factors to consider for your infrastructure such as overhead
He had one intriguing point about a potential organization that could influence DNSSEC deployment:
There is one organization, however, that is in a surprisingly strong position to influence the uptake of DNSSec: the PCI Security Standards Council, responsible for the development of the PCI Data Security Standard and other standards governing the payment card industry. Longstanding rumors say the organization is considering requiring companies whose websites accept payment cards to use DNSSec to sign their zones in order to achieve PCI DSS compliance. Given how pervasive acceptance of credit cards is on major websites, such a requirement would have vast reach.
That rumor is interesting to hear and certainly something we’ll be exploring through various connections to learn more about what might be possible.
I was surprised, though, that Cricket did not mention what I see as one of the strongest motivations to deploy DNSSEC right now – the ability to then use the DANE protocol to provide an additional layer of trust to TLS and SSL certificates. As Andrew recently wrote, DANE has a great ability to increase the overall security of TLS/SSL certificates by ensuring that users are receiving the correct TLS certificates that you want them to be using. We’re already seeing a great uptake in DANE / DNSSEC usage within the XMPP/Jabber community as well as within various email services as a way of authenticating mail servers and helping fight spam.
I also felt the article dealt a bit longer than needed on some of the past history of DNSSEC and some of the earlier issues that slowed deployment, rather than focusing on the fact that those obstacles have been overcome and the tools and solutions are MUCH easier now.
Overall, though, this is a good article and it’s good to have it out there on a widely-read site such as InfoWorld.
If you would like to get started with DNSSEC – because Cricket is right, the time to start is NOW! – please visit our “Start Here” page to find resources targeted for the type of role you have. Or jump directly to our DNSSEC page and browse some of the links and information you find there.
See the discussion of this InfoWorld article on:
Aug 04
IPFire Adds DNSSEC Validation In New Release Via Crowdfunding
We were pleased to see an announcement from the IPFire open source firewall distribution indicating that DNSSEC validation had been added to their most recent “IPFire 2.15 – Core Update 80″ yesterday. More intriguing to me, perhaps, was that the DNSSEC validation was added to the software distribution via a crowdfunding initiative for their “wishlist”. While I realize this is not unique among software products, it was great to see that some number of IPFire users felt DNSSEC was important enough to donate to prioritize this task. [Tip for IPFire: It would be nice to know how many users donated rather than just the total amount.]
I will admit I’d not heard of IPFire prior to seeing a tweet about the DNSSEC addition this morning, but in looking at their “About IPFire” page it seems to have the kind of services that I would want in a system like this. (I run a similar type of hardened Linux distribution on my own home server/gateway.)
This news about IPFire is important because getting DNSSEC validation to happen on the edge of local networks is a critical step in the plan for where DNSSEC validation needs to happen. Ideally, of course, we’d get the validation happening in the device operating systems and even applications, but getting the validation on the edge of the local network does minimize the attack surface significantly!
Kudos to the team at IPFire for doing this work – and for the IPFire users who crowdfunded it!
P.S. Do you know of another firewall software distribution that we should add to our list on the plan for DNSSEC validation? Please do let us know as we’d definitely like to expand the list we have there. And if you don’t know much about DNSSEC, check out our “Start Here” page to learn how to get started…
Aug 04
FIR #767 – 8/4/14 – For Immediate Release
Jul 30
The Mobile Messaging Wars – and Why Facebook Is Forcing Users to Use Its Messenger App (Featured Blog)
Jul 30
Heading To A "Junior Curling Camp" This Weekend
Yes, curling... that winter sport.
In July. :-)
And yes, I'm excited! I'm taking two vacation days to bring my 12-year-old daughter Chloe down to this Junior Curling Camp sponsored by the Grand National Curling Club (GNCC), the organization that helps coordinate the sport of curling along the eastern coast of the USA.
Chloe absolutely loves the sport and has been curling for the past three years in the Petersham Curling Club youth curling program down in Petersham, MA, about 45 minutes south of where we live in Keene, NH. This past year she was a skip (captain) for one of our Petersham "Little Rocks" teams (ages 7-11) and did quite well in a couple of bonspiels (tournaments).
Now as a 12-year-old she'll be going into the "Juniors" program and playing at a more serious level with kids ages 12 up to 21-ish. When we were talking earlier this year about what to do this summer, this curling camp rose right to the top of her choices. :-) So we're heading down to join 31 other kids from around the region for what should be a couple of pretty intense days. It starts tomorrow (Thursday, July 31, 2014) afternoon and goes through Sunday mid-day. Lots of practice sessions, individual coaching, classroom work and some games.
The fun part for me is that I also get to join in the action as a coaching assistant. The camp will have some high-level coaches and instructors from the US Curling Association and from national teams, but they invited other club coaches to help... and I jumped right in. I'm very much looking forward to learning a great deal over the next few days from the other coaches that I can bring back to our Petersham CC youth program, as well as for the Monadnock Curling Club effort we are trying to start up in Keene.
So that's the plan... curling... in July... in Pennsylvania! :-)
Jul 30
Call For Proposals: DNSSEC Workshop at ICANN 51 in L.A. on October 15, 2014
Do you have an idea for a better way to work with DNSSEC? Have you created a new tool or service for DNSSEC or DANE that you would like to present to the wider community? Could you provide a “case study” of how you implemented DNSSEC within your organization? Have you started using DANE to secure your email communication?
If you would be interested in speaking about any of those points – or any of the other topics we have listed below, WE WOULD LIKE TO HEAR FROM YOU! We’re working on creating the program for the ICANN 51 DNSSEC Workshop that will be held in Los Angeles on October 15, 2014. As you’ll note in the full call for participation included below, we are in particular seeking participants on three topics:
- DANE / DNSSEC as a way to secure email
- Potential impacts of Root Key Rollover
- Experiences from new gTLD registries and administrators
If you have any ideas, or would like to ask questions about what is involved with the workshop, please email us at dnssec-losangeles@isoc.org. Initially, we don’t need a full abstract – just a couple of sentences about what you would like to speak about is perfectly fine.
Thanks,
Dan
Call for Participation — ICANN DNSSEC Workshop 15 October 2014
The DNSSEC Deployment Initiative and the Internet Society Deploy360 Programme, in cooperation with the ICANN Security and Stability Advisory Committee (SSAC), are planning a DNSSEC Workshop at the ICANN 51 meeting in Los Angeles, California, on 15 October 2014. The DNSSEC Workshop has been a part of ICANN meetings for several years and has provided a forum for both experienced and new people to meet, present and discuss current and future DNSSEC deployments.
For reference, the most recent session was held at the ICANN meeting in London on 25 June 2014. The presentations and transcripts are available at: http://london50.icann.org/en/schedule/wed-dnssec.
We are seeking presentations on the following topics;
1. DNSSEC activities in the North America region
For this panel we are seeking participation from those who have been involved in DNSSEC deployment in the North America region and also from those who have not deployed DNSSEC but who have a keen interest in the challenges and benefits of deployment. In particular, we will consider the following questions:
- What can DNSSEC do for you?
- What doesn’t it do?
- What are the internal tradeoffs to implementing DNSSEC?
- What did you learn in your deployment of DNSSEC?
We are interested in presentations from both people involved with the signing of domains and people involved with the deployment of DNSSEC-validating DNS resolvers.
2. DANE / DNSSEC as a way to secure email
The DNS-based Authentication of Named Entities (DANE) protocol is an exciting development where DNSSEC can be used to provide a strong additional trust layer for traditional SSL/TLS certificates. We are both pleased and intrigued by the growing usage of DANE and DNSSEC as a means of providing added security for email. Multiple email servers have added support for DANE records to secure TLS/SSL connections. Some email providers are marketing DNSSEC/DANE support. We would like to have a panel at ICANN 51 focusing on this particular usage of DANE. Are you a developer of an email server or client supporting DANE? Do you provide DANE / DNSSEC support in your email service? Can you provide a brief case study of what you have done to implement DANE / DNSSEC? Can you talk about any lessons you learned in the process?
3. Potential impacts of Root Key Rollover
Given many concerns about the need to do a Root Key Rollover, we would like to bring together a panel of people who can talk about what the potential impacts may be to ISPs, equipment providers and end users, and also what can be done to potentially mitigate those issues. In particular, we are seeking participation from vendors, ISPs, and the community that will be affected by distribution of new root keys. We would like to be able to offer suggestions out of this panel to the wider technical community. If you have a specific concern about the Root Key Rollover, or believe you have a method or solution to help address impacts, we would like to hear from you.
4. New gTLD registries and administrators implementing DNSSEC
With the launch of the new gTLDs, we are interested in hearing from registries and operators of new gTLDs about what systems and processes they have implemented to support DNSSEC. As more gTLDs are launched, is there DNSSEC-related information that can be shared to help those launches go easier?
5. The operational realities of running DNSSEC
Now that DNSSEC has become an operational norm for many registries, registrars, and ISPs, what have we learned about how we manage DNSSEC?
- What is the best practice around key rollovers?
- How often do you review your disaster recovery procedures?
- Is there operational familiarity within your customer support teams?
- What operational statistics have we gathered about DNSSEC?
- Are there experiences being documented in the form of best practices, or something similar, for transfer of signed zones?
6. DNSSEC automation
For DNSSEC to reach massive deployment levels it is clear that a higher level of automation is required than is currently available. Topics for which we would like to see presentations include:
- What tools, systems and services are available to help automate DNSSEC key management?
- Can you provide an analysis of current tools/services and identify gaps?
- Where are the best opportunities for automation within DNSSEC signing and validation processes?
- What are the costs and benefits of different approaches to automation?
7. When unexpected DNSSEC events occur
What have we learned from some of the operational outages that we have seen over the past 18 months? Are there lessons that we can pass on to those just about to implement DNSSEC? How do you manage dissemination of information about the outage? What have you learned about communications planning? Do you have a route to ISPs and registrars? How do you liaise with your CERT community?
8. DANE and DNSSEC applications
There is strong interest for DANE usage within web transactions as well as for securing email and Voice-over-IP (VoIP). We are seeking presentations on topics such as:
- What are some of the new and innovative uses of DANE and other DNSSEC applications in new areas or industries?
- What tools and services are now available that can support DANE usage?
- How soon could DANE and other DNSSEC applications become a deployable reality?
- How can the industry use DANE and other DNSSEC applications as a mechanism for creating a more secure Internet?
We would be particularly interested in any live demonstrations of DNSSEC / DANE applications and services. For example, a demonstration of the actual process of setting up a site with a certificate stored in a TLSA record that correctly validates would be welcome. Demonstrations of new tools that make the setup of DNSSEC or DANE more automated would also be welcome.
9. DNSSEC and DANE in the enterprise
Enterprises can play a critical role in both providing DNSSEC validation to their internal networks and also through signing of the domains owned by the enterprise. We are seeking presentations from enterprises that have implemented DNSSEC on validation and/or signing processes and can address questions such as:
- What are the benefits to enterprises of rolling out DNSSEC validation? And how do they do so?
- What are the challenges to deployment for these organizations and how could DANE and other DNSSEC applications address those challenges?
- How should an enterprise best prepare its IT staff and network to implement DNSSEC?
- What tools and systems are available to assist enterprises in the deployment of DNSSEC?
- How can the DANE protocol be used within an enterprise to bring a higher level of security to transactions using SSL/TLS certificates?
10. Guidance for Registrars in supporting DNSSEC
The 2013 Registrar Accreditation Agreement (RAA) for registrars and resellers requires them to support DNSSEC from January 1, 2014. We are seeking presentations discussing:
- What are the specific technical requirements of the RAA and how can registrars meet those requirements?
- What tools and systems are available for registrars that include DNSSEC support?
- What information do registrars need to provide to resellers and ultimately customers?
We are particularly interested in hearing from registrars who have signed the 2013 RAA and have either already implemented DNSSEC support or have a plan for doing so.
11. Implementing DNSSEC validation at Internet Service Providers (ISPs)
Internet Service Providers (ISPs) play a critical role by enabling DNSSEC validation for the caching DNS resolvers used by their customers. We have now seen massive rollouts of DNSSEC validation within large North American ISPs and at ISPs around the world. We are interested in presentations on topics such as:
- What does an ISP need to do to prepare its network for implementing DNSSEC validation?
- How does an ISP need to prepare its support staff and technical staff for the rollout of DNSSEC validation?
- What measurements are available about the degree of DNSSEC validation currently deployed?
- What tools are available to help an ISP deploy DNSSEC validation?
- What are the practical server-sizing impacts of enabling DNSSEC validation on ISP DNS Resolvers (ex. cost, memory, CPU, bandwidth, technical support, etc.)?
12. APIs between the Registrars and DNS hosting operators
One specific area that has been identified as needing focus is the communication between registrars and DNS hosting operators, specifically when these functions are provided by different entities. Currently, the communication, such as the transfer of a DS record, often occurs by way of the domain name holder copying and pasting information from one web interface to another. How can this be automated? We would welcome presentations by either registrars or DNS hosting operators who have implemented APIs for the communication of DNSSEC information, or from people with ideas around how such APIs could be constructed.
13. Hardware Security Modules (HSMs) use cases and innovation
We are interested in demonstrations of HSMs, presentations of HSM-related innovations and real world use cases of HSMs and key management.
In addition, we welcome suggestions for additional topics.
If you are interested in participating, please send a brief (1-2 sentence) description of your proposed presentation to dnssec-losangeles@isoc.org by Friday, 13 August 2014
We hope that you can join us.
Thank you,
Julie Hedlund
On behalf of the DNSSEC Workshop Program Committee:
Steve Crocker, Shinkuro
Mark Elkins, DNS/ZACR
Cath Goulding, Nominet UK
Jean Robert Hountomey, AfricaCERT
Jacques Latour, .CA
Xiaodong Lee, CNNIC
Luciano Minuchin, NIC.AR
Russ Mundy, Sparta/Parsons
Ondřej Surý, CZ.NIC
Yoshiro Yoneya, JPRS
Dan York, Internet Society
