Preparation for Recitation on DNSSEC

Read "Security Vulnerabilities in DNS and DNSSEC" by Ariyapperuma and Mitchell. This paper is about DNSSEC. DNS, as is, is an insecure system; DNSSEC is a proposed extension to DNS to mitigate some of the security concerns. It is not yet widespread.

As you read, think about

Reflection Questions

Below are three questions for you to reflect on as you read the paper. You will post your reflection, or respond to another student's reflection, on your Teaching Team Piazzas. You do not need to email responses to these questions to your TA. As a reminder:

Now, for the questions themselves. There are many possibile answers for each. We're expecting you to thoughtfully consider these questions, not come up with the single "best" answer. Your answers to these questions should be in your own words, not direct quotations from the paper.

  1. DNSSEC has not been fully deployed. What do you think is preventing that?
  2. Who should be in charge of the root key? (You can read about the root key process here; it's one of Katrina's absolute favorite things.)
  3. Suppose we were still on campus, and wanted to have you act out DNSSEC in recitation. How would you design that activity? How would you illustrate the ways in which DNSSEC differs from DNS? (We got great responses to this question last week with Raft. Typically we have students act out both Raft and DNSSEC.)