[HN Gopher] Secure Domain Name System (DNS) Deployment 2026 Guid...
___________________________________________________________________
Secure Domain Name System (DNS) Deployment 2026 Guide [pdf]
Author : XzetaU8
Score : 85 points
Date : 2026-03-24 12:14 UTC (10 hours ago)
(HTM) web link (nvlpubs.nist.gov)
(TXT) w3m dump (nvlpubs.nist.gov)
| bob1029 wrote:
| > ECC algorithms with smaller key sizes would be more vulnerable
| to a quantum attack, as it would require a currently theoretical
| quantum computer with fewer qubits than would be required for an
| RSA key with the same cryptographic strength [25].
|
| This is what keeps me skeptical about ECC. RSA is really chunky,
| and maybe that's a fundamental advantage from an information
| theory perspective. Compromising on the crypto scheme because we
| can't fit inside UDP seems like a cursed path.
|
| [25]: https://arxiv.org/abs/1706.06752
| phicoh wrote:
| If we are looking at the RSA factoring challenge
| (https://en.wikipedia.org/wiki/RSA_Factoring_Challenge) then
| 768 bits is done. Breaking RSA 1024 is assumed to be possible
| but has not been demonstrated in public.
|
| So maybe quantum computers should first complete some of these
| RSA challenges with less compute resources than done
| classically before considering any claims about qubits needs as
| practical.
|
| All of this in the context of DNSSEC or other system using
| signatures. For encryption the story is different.
| tptacek wrote:
| A CRQC makes both RSA and ECDLP practically irrelevant. The
| qubit thresholds between available ECC and RSA-2048 don't look
| meaningful. If you're worried about QC, get comfortable with
| lattices.
|
| Of course, this part of the NIST recommendation doesn't matter,
| because DNSSEC is moribund. If we want post-quantum record
| authenticity, we should go back to the drawing board and come
| up with something that doesn't depend on UDP (and that doesn't
| carry DNSSEC's 1994-vintage offline-signer compromise and all-
| or-nothing zone signature compromise).
| gumarn_y wrote:
| Yeah if we will ever see a CRQC...but nevertheless we will
| migrate to PQC as it will be forced via regulations thx to
| lobby work by Mosca and friends
| progbits wrote:
| > 864000 seconds (1 day)
|
| Could use some proofreading.
| antonyh wrote:
| I do wish these types of document were published as HTML and not
| just as PDF.
| layer8 wrote:
| It would be nice if there was an HTML/A standard. Though this
| document isn't PDF/A either.
| kgwxd wrote:
| Firefox makes it look like HTML with pdf.js. Wouldn't it be
| trivial to make something that puts a PDF through that same
| filter and saves the results to a file? Or do you mean by
| default so you can just read it in a browser without PDF
| support?
___________________________________________________________________
(page generated 2026-03-24 23:01 UTC)