15 comments

  • dmm25 minutes ago
    I switched to deSEC because they allow you to create tokens for DNS-01 validation which are tightly scoped to a single subdomain. This means I have a VM running &quot;service1.foo.example.com&quot; which is not publicly available but can still get certs from letsencrypt, but with a token that can&#x27;t be used to issue certs for other domains.<p>It works great!
  • awill4 hours ago
    I signed up and saw they only allowed a single subdomain for DDNS, with docs saying to contact support if you needed more. I emailed asking for just 1 more subdomain and support told me that for my usecase I should just use CloudFlare.<p>So I did. No silly miniscule restrictions.
    • imoverclocked51 minutes ago
      I had this issue with cloudns and a single record with an IPv4 and IPv6 address. They only allowed one free ddns record which covered exactly one protocol. On top of that, they added records to resolve unknown names for advertising purposes.<p>I get that it costs money to run a DNS service but it seems like it should be a lot cheaper at scale than a lot of companies are providing.
    • boramalper4 hours ago
      Similar story: asked for an increase and got told<p>&gt; […] our mission is to improve Internet security by increasing the adoption of DNSSEC. [We therefore expect users to enable DNSSEC for their domains.<p>&gt; Would you be willing to do that?<p>Wanting to increase the adoption of DNSSEC is fair, but couldn’t this be all self-serve? It’s almost as if they don’t want people to use them.
      • 8by33 hours ago
        They&#x27;ve actually just done that, your limit automatically gets increased if all your domains are secured.
        • boramalper3 hours ago
          That’s good to know! I was actually very excited when I first found them; I was surprised that there aren’t many free&#x2F;open public DNS hosting services.
  • zetanor4 hours ago
    When I last tried deSEC, the service was reliable and well worth the price of admission, but the web UI and API were both quite rough, and propagation tended to be quite slow. It was annoying to do an ACME DNS01 challenge on it, for example. IIRC, the API didn&#x27;t have a complete set of replace&#x2F;edit endpoints, so even DNSControl (<a href="https:&#x2F;&#x2F;github.com&#x2F;DNSControl&#x2F;dnscontrol" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;DNSControl&#x2F;dnscontrol</a>) would leave records nonexistent for a while while during updates.<p>As an aside (though this certainly applies to deSEC) it&#x27;s strange to me how so many DNS services (free or paid) struggle to import simple Bind zone files, often either giving a vague error (&quot;one or more records could not be imported&quot;), mangling records, or even just silently omitting records. Parsing a zone file has some gotchas, but it doesn&#x27;t seem like it should be <i>that</i> hard.
    • dzogchen9 minutes ago
      &gt; well worth the price of admission<p>A strange thing to say about something that is free
  • TheBozzCL1 hour ago
    I literally just switched away from Hurricane Electric to deSEC. The only real issue that I had with HE, but it&#x27;s a big one, is that they don&#x27;t allow wildcard CNAMEs. I consider that important for the security of some sensitive endpoints that I have no choice but to expose publicly. Those endpoints are well protected with 2FA and heavily monitored, but I wanted to be able to use randomized subdomains to at least have some obfuscation on top.
  • aequitas4 hours ago
    Recently migrated to deSEC, great experience so far, except for hitting the API rate limit when using Tofu to plan and apply changes with around a 100 domains. For now I&#x27;m using `-parallelism=1` which seems to work.
  • Stitch42235 hours ago
    We found deSEC to be the only affordable DNS supplier in the EU that complies with state of the art secure DNSSEC. Highly recommended.
    • dsl4 hours ago
      DNSSEC support is an anti-feature, it is dead&#x2F;dying and the faster we can unburden ourselves from it the faster we can move on to better solutions.<p><a href="https:&#x2F;&#x2F;sockpuppet.org&#x2F;blog&#x2F;2015&#x2F;01&#x2F;15&#x2F;against-dnssec&#x2F;" rel="nofollow">https:&#x2F;&#x2F;sockpuppet.org&#x2F;blog&#x2F;2015&#x2F;01&#x2F;15&#x2F;against-dnssec&#x2F;</a>
      • teddyh2 hours ago
        Rebuttal: &lt;<a href="https:&#x2F;&#x2F;easydns.com&#x2F;blog&#x2F;2015&#x2F;08&#x2F;06&#x2F;for-dnssec&#x2F;" rel="nofollow">https:&#x2F;&#x2F;easydns.com&#x2F;blog&#x2F;2015&#x2F;08&#x2F;06&#x2F;for-dnssec&#x2F;</a>&gt;
        • dsl1 hour ago
          That rebuttal held water 10 years ago, but fortunately we have made a lot of advancements since then.<p>DNSSEC was a solution trying to solve the problem of DNS security while still maintaining transparency for DNS operators to spy on queries. At the time, passive DNS was one of the tent poles of tracking malware and responding to security incidents.<p>We have since committed entirely to transport security in the form of DoH and friends. It solves the vast majority of problems we actually have.
      • Stitch42231 hour ago
        Such as? And do those solve the same thing? The post lists 8 headlines why it should be abolished.
      • apefulsin4 hours ago
        So DNS should be open to MITM attackers?
        • icedchai51 minutes ago
          Even with DNSSEC, it still is. Example: <a href="https:&#x2F;&#x2F;blog.cloudflare.com&#x2F;de-tld-outage-dnssec&#x2F;" rel="nofollow">https:&#x2F;&#x2F;blog.cloudflare.com&#x2F;de-tld-outage-dnssec&#x2F;</a>
    • traceroute664 hours ago
      &gt; We found deSEC to be the only affordable DNS supplier in the EU that complies with state of the art secure DNSSEC.<p>I mean, if your definition of &quot;affordable&quot; is free, then sure.<p>But for the record there are other affordable EU suppliers who do DNSSEC:<p><pre><code> - Bunny DNS[0] is &quot;free&quot; – i.e. only subject to their minimum $1&#x2F;month account spend fee. - RcodeZero is very affordable[1] plus added bonus it is run by the `.at` registry so the infrastructure is solid – business customers only, no private individuals - Netnod (only via resellers[2] unless you are a big company or government) – Netnod host the I Root Servers and their public hosting DNSSEC service will soon feature HSM-bound DNSSEC keys </code></pre> [0] <a href="https:&#x2F;&#x2F;bunny.net&#x2F;dns&#x2F;" rel="nofollow">https:&#x2F;&#x2F;bunny.net&#x2F;dns&#x2F;</a> [1] <a href="https:&#x2F;&#x2F;www.rcodezero.at&#x2F;solutions&#x2F;enterprise" rel="nofollow">https:&#x2F;&#x2F;www.rcodezero.at&#x2F;solutions&#x2F;enterprise</a> [2] <a href="https:&#x2F;&#x2F;www.netnod.se&#x2F;dns&#x2F;find-a-partner" rel="nofollow">https:&#x2F;&#x2F;www.netnod.se&#x2F;dns&#x2F;find-a-partner</a>
      • quicksilver033 hours ago
        I happen to run an affordable EU supplier who does DNSSEC, and also AXFR (incoming and outgoing). I offer a free plan from time to time, but not at the moment to preserve resources for paying customer.<p><a href="https:&#x2F;&#x2F;www.ptrdns.net&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.ptrdns.net&#x2F;</a>
        • andreaso2 hours ago
          Are you aware that the child zone A(AAAA) records for danube.ns.ptrdns.net differs from the parent zone A(AAA) glue records for danube.ns.ptrdns.net?<p>Looks like it&#x27;s the glue records that point to the actual server?
      • Stitch422356 minutes ago
        We have a support ticket at Bunny that has been open for months precisely because they don’t provide state-of-the-art DNSSEC. We had to move to another provider, as we have a deadline to comply with at the end of this month. I don’t know what the issue is off the top of my head.<p>Netnod.se uses a DNSKEY that is too small on their main domain.<p>Rcodezero.at might indeed be something. Thanks.<p>We donate to deSEC, so it’s not free for us.
      • amaccuish4 hours ago
        One who doesn&#x27;t is frustratingly Hetzner.
  • lacoolj2 hours ago
    Is this somehow related to the other post about another service shutting down its encrypted DNS?<p><a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=49568579">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=49568579</a><p>Weird timing?
  • MattTheRealOne3 hours ago
    I have been using deSEC for a couple of years without any issues. I mostly just do not want my DNS handled by my registrar so that I can easily transfer domains without worrying about DNS as well, and I do not like how centralized the internet is becoming around Cloudflare.
  • 8by33 hours ago
    Happy deSec user, use them for all my domains. Had quick thoughtful replies from Peter if I had any questions.
  • anonymousiam4 hours ago
    Seems legit, but how can I trust them to survive if they&#x27;re not collecting revenue?
    • bflesch4 hours ago
      Some of them are located in Virginia, don&#x27;t worry they&#x27;ll be funded forever.
  • bflesch4 hours ago
    After recent US shenanigans why would you spend effort to migrate to yet another Five Eyes controlled service, especially if they do the full &quot;privacy from Germany&quot; circus.<p>What kind of security threat does a migration to such a service actually mitigate?<p>If they were truly a &quot;sovereign EU&quot; kind of project then they&#x27;d be on .eu domain, not have security advisors from Virginia, and so on.<p>Nevertheless it&#x27;s good to see that the decoupling-from-your-allies movement that US citizens have initiated is so scary that they have to set up these kind of fake EU alternatives with some local figureheads.
  • ak41535 hours ago
    Just use unbound
    • craftkiller3 hours ago
      My solution was to self-host PowerDNS and then sign up for the free DNS mirroring from hurricane electric. That way, I can administer my DNS records any way I want (these days I usually just manually edit PowerDNS&#x27;s sqlite database) and if&#x2F;when my PowerDNS server goes down, hurricane electric is still serving my records so the domain keeps resolving fine.
    • 0l5 hours ago
      Completely different thing
      • thesuitonym4 hours ago
        What is this if not a DNS service?
        • pacija4 hours ago
          Unbound is caching, not authoritative. Zones with dns records are served from authoritative DNS servers such as bind. Unbound asks authoritative servers for records and caches them locally, giving faster response and reducing load on authoritative servers.
      • pacija4 hours ago
        Just use bind :)
  • iAMkenough3 hours ago
    Homepage looks busted on Orion iOS. Signup form has you entering your email address within the yellow “Create Account” button.
  • cyberax5 hours ago
    Does not support AXFR :(
    • 8organicbits5 hours ago
      That&#x27;s a bummer.<p>It looks like they are open to adding the feature and open to outside contributions: <a href="https:&#x2F;&#x2F;github.com&#x2F;desec-io&#x2F;desec-stack&#x2F;issues&#x2F;579" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;desec-io&#x2F;desec-stack&#x2F;issues&#x2F;579</a>
  • mhmdfromkarak3 hours ago
    do what&#x27;s best.