
11/10/2015 · Dani Grant
What this post added
This post announces the launch of Universal DNSSEC, making DNSSEC available for free to all Cloudflare customers. It details the vulnerability in DNS that DNSSEC addresses (lack of authentication leading to man-in-the-middle attacks). It explains how trust is delegated in DNSSEC and the manual process of activation involving registrars. To overcome these limitations, Cloudflare is proposing a new Internet Draft protocol for direct communication between DNS providers and registries/registrars to automate DNSSEC activation. The post highlights early successes with registries and registrars supporting ECDSA, Cloudflare's chosen cipher, and encourages broader adoption.