The secret group that keeps the internet secure is changing the key that protects DNS and most people will never notice – unless AI-written code has rolled its own DNS configuration.
When I got an invitation to talk to IANA's @kimdavies.com about bizarre ultra-technical rituals, I was expecting a plea to bust the myths of the 'seven keys of the Internet'. But this isn't just the fascinating mix of security and transparency making up key ceremonies: it's DNS key rollover time!
Just as the regular key signing ceremonies are a combination of the arcane, the technical and the banal, the key rollover is a really big deal that will happen on October 11th, likely with hardly anyone noticing apart from the people who've been working hard on this for a few years already
Unfortunately, part of the reason that changing the apex key used to sign the entire chain of signatures that secure the keys that secure DNS is how low adoption DNSSEC remains; I crack a lot of DNS jokes and even I missed the rollover issues in Germany and Austria earlier this year
As well as IANA's very clear guidance on what to do (make sure your DNS software is up to date, check any custom configurations you might have AI coded without really noticing), I also dig into why DNS got security so recently and whether it matters that the global DNS ceremonies happen in the US.
If you have any network responsibilities, put October 11th on your calendar: that's when the DNS root key signing key rolls over to a new key that should already be in your configuration. That rollover will now happen every 3 years and you probably need automated tests rather than calendar reminders
Writing this piece was an opportunity for friends to send me their excellent collections of DNS memes (alas too spicy to convince my editor to use them), an opportunity to look back at my conversations with Paul Mockapetris over the years and a punch in the feels remembering we lost Dan Kaminsky
DNS
DNSSEC
key rollovers
IANA
global internet governance
Dan Kaminsky
Cloudflare Radar