No video

DNSSec Explained

  Рет қаралды 72,020

Daniel Benway

Daniel Benway

8 жыл бұрын

In this video I diagrammatically show how DNSSec works. We’ll look at DNS functionality, DNS referrals, spoofing and man-in-the-middle attacks, asymmetric key cryptography (public key cryptography), digital signatures, zone signing keys, key signing keys, DS records, and more.

Пікірлер: 57
@keerthisreenivaskonjety1897
@keerthisreenivaskonjety1897 4 ай бұрын
I was looking up for your blog. RIP, you are making an impact event after you left this world! amazing explanation.
@luislo01
@luislo01 5 жыл бұрын
Terribly good explained. There are tons of videos pretending to explain DNSSec, yours do it for real!!! Very well done. Thanks a lot.
@chennaikidi
@chennaikidi 5 жыл бұрын
Very well presented. Have seen a lot of content for DNSSec but havent found anything as clear and concise as this.
@rafafilho11
@rafafilho11 3 жыл бұрын
Great explanation, I lost some hours trying to understand the DNSSec and now, I got everything I need. Thanks for the good material.
@thebpandey
@thebpandey 6 жыл бұрын
This was great! Clear explanations.Thanks for taking the time to make this.
@fantuznet
@fantuznet 6 жыл бұрын
bravo! clear, quick, intense. interetesting !
@Ali-ok8yn
@Ali-ok8yn 3 жыл бұрын
The best explanation of DNSSEC on youtube
@allanjoarder27
@allanjoarder27 8 жыл бұрын
Thank you for the awesome explanation!
@alientezam18
@alientezam18 4 жыл бұрын
Very well explained. Thank you !!!
@Pedro-fd9tv
@Pedro-fd9tv Жыл бұрын
Best video on the subject, thank you for the explanation.
@Protonumus
@Protonumus 4 жыл бұрын
Great job interpreting DNSSec for secure domains. Google's future prospects on the Internet include encryption - a secure connection (HTTPS) is required for all websites. Google has implemented unsafe warnings for domains. Google will block (HTTP) domains next year or so.
@123norway
@123norway Жыл бұрын
A very clear explanation! Thank you good sir!
@KartikGajaria
@KartikGajaria Жыл бұрын
Thanks for such a simple and clear explanation.
@colunizator
@colunizator 6 жыл бұрын
Yooo man You are the real MVP Current MCSA books don't give a thing about this terminology and explanation Edit: I don't have any DNS practice, and i was struggling understanding DNSSEC from 70-741 exam Thanks a lot
@tomasplachy884
@tomasplachy884 4 жыл бұрын
This is a great video, but it would be even better, if you highlighted the parts you are currently talking about (since it is a bit difficoult to orientate in all the items). Anyway thanks for the explanation, it helped a lot.
@sheikhbaseer3799
@sheikhbaseer3799 4 жыл бұрын
Awesome Explanation...Kudos.
@vinylshetty1
@vinylshetty1 4 жыл бұрын
very good video. cleared the concept . cloudflare also has some good articles / blogs written on dnssec and complexities it brings in.this video and those blogs should be good starting point for everyone
@preetidutta5660
@preetidutta5660 6 жыл бұрын
Awesome slides Daniel
@hamidullahmuslih6301
@hamidullahmuslih6301 4 жыл бұрын
thank you sooooo much that was awesome
@faazk
@faazk 7 жыл бұрын
Does this mean dnssec is not depended on HTTPS digital signatures? so digital signatures we receive on HTTPS are different to digital certificate of DNSSEC?
@threeone6012
@threeone6012 3 жыл бұрын
Fantastic explanation! Somebody needs to put you in charge of something. You know what you're talking about.
@cloudbuddytechsource8532
@cloudbuddytechsource8532 2 жыл бұрын
Daniel, can you please share the reference/blog links. your information really helped a lot. Great work 👍
@CyberJuke5
@CyberJuke5 5 ай бұрын
If there's a malicious server pretending to be the original one, isn't there a way to know the difference between them, for example, in the URL?
@PETAJOULE543
@PETAJOULE543 5 жыл бұрын
Motivation of DNSSEC and also its detailed explanation. Also, the difference between iterative and recursive dns queries.
@fbifido2
@fbifido2 6 жыл бұрын
@9:02 why not just encrypt the request with the root pubksk, then send it to the root server, with your own public-key?
@IPv6people
@IPv6people 2 жыл бұрын
Thanks indeed for this explanation. DNSSEC still does not give the impression of a simple system. Could that be the reason for the limited implementation?
@Valdemore4
@Valdemore4 2 жыл бұрын
Great video
@nahdude2457
@nahdude2457 5 жыл бұрын
A goog presentation does not make its presenter obsolete. This does! A more visually supportive presentation would have been miles better and easier to create.
@GoldenGecko
@GoldenGecko 2 жыл бұрын
good stuff
@valentecaio
@valentecaio 3 жыл бұрын
thanks a lot!
@saraibrown9649
@saraibrown9649 3 жыл бұрын
Great video but I would recommend raising the volume a bit. I struggled to hear you even with my volume all the way up. I appreciate the effort regardless!
@peterc.7841
@peterc.7841 Жыл бұрын
Thanks so much, very helpful. If it's still completely valid, you may want to upload it afresh, to have a newer date.
@pear7777
@pear7777 10 ай бұрын
"Who needs it?" "Everyone!"
@TheHynky
@TheHynky 7 жыл бұрын
Great video even dummy as me got it.
@fbifido2
@fbifido2 6 жыл бұрын
why can't the Root zone, be the one to comunicate to the TLD, then the TLD comminicate with the DBL zone, all using dnssec, then the root reply with the correct answer?
@Stilgarsan
@Stilgarsan 5 жыл бұрын
This would put extra strain on the root servers. The DNS protocol is designed to avoid such things.
@dankierson
@dankierson Ай бұрын
You have to study this to get it all but the gist of it is clear - DNSSEC makes it harder to hijack a web request by having domain name servers retain records for a domain that allow an independent server to validate it before the user connects with it.
@asheesha68
@asheesha68 2 жыл бұрын
Very nice presentation.. but perhaps you forgot to explain what is DNSKey
@jpdstan
@jpdstan 7 жыл бұрын
Very well made slides! Although I don't really think there's a point to making this a video/narrating over it if you just read completely off the slides.
@bevo260578
@bevo260578 3 жыл бұрын
cool
@v1rtu4l
@v1rtu4l 7 жыл бұрын
on 4:05 your picture says that Jamie Lee does decrypt a digest encrypted by Arnolds private key by using Arnold's public key. By definition you can not decrypt with a public Key. i think you meant that Jamie Lee does encrypt the hash of the sent document and then compare that to the send encrypted digest. am i right ?
@Sevlowwolf
@Sevlowwolf 6 жыл бұрын
I'm a little confused by this question. in asymmetrical cryptography you encrypt something using your own private key, then can send it to whomever you like and include your public key. In the example Jamie Lee can then run his own hash on the document, and run another hash on the decrypted digest using the public key and if they both match, this ensures integrity.
@pazi95
@pazi95 6 жыл бұрын
I think the correct terminology should have been that Arnold generates a digital signature using his private key, and then Jamie Lee verifies that signature using Arnold's public key. For encryption, the key pair would be used the opposite way, the public key is used to encrypt which can then be decrypted using the private key.
@ianporter9740
@ianporter9740 3 жыл бұрын
"special shoutout to al gore" omegalul xDD
@quadraticfunction8045
@quadraticfunction8045 4 жыл бұрын
Good attempt and appreciate your effort , BUT the font on slides is so hard to read and wrong colour scheme used for the diagrams.
@miriyalajeevankumar5449
@miriyalajeevankumar5449 5 жыл бұрын
DNS sec starts at kzbin.info/www/bejne/lWmwkKmre8iXkLc
@fbifido2
@fbifido2 6 жыл бұрын
very low volume+++++++++++
@mcnogard1552
@mcnogard1552 7 жыл бұрын
(deleted)
@mcnogard1552
@mcnogard1552 7 жыл бұрын
3:24 I disagree with this. If Arnold hash using Arnolds private key, then everyone can decrypt Arnolds message with Arnolds public key.
@mcnogard1552
@mcnogard1552 7 жыл бұрын
What should have happened is that Arnold use Jamie Lee's public key to hash his message, then Jamie Lee can open the message with his private key. But nobody else can see the message.
@danielbenway6599
@danielbenway6599 7 жыл бұрын
I’m afraid you’re incorrect. If you do a little bit more research, I think you’ll see why.It seems that you might be confusing the asymmetric key encryption (public key encryption) of a document with the digital signing of a document.Next, consider the following thought experiment: if Arnold wanted to digitally sign an unencrypted document and then give it to millions of different recipients, how would he sign that document?Lastly, I prefer to answer these questions on my blog.Thanks, and have a great day!
@mcnogard1552
@mcnogard1552 7 жыл бұрын
So DNSsec is not using RSA for signing?
@emiltarandash5056
@emiltarandash5056 6 жыл бұрын
Very complicated explanation, not so clear. Lacks some real examples including real keys and records. Too theoretical
@dahomie1620
@dahomie1620 Жыл бұрын
Awesome thanks for helping my understand dnssec better!
HTTPS, SSL, TLS & Certificate Authority Explained
43:29
Laith Academy
Рет қаралды 83 М.
DNSSEC  What it is and what it isn't
40:38
NANOG
Рет қаралды 7 М.
Inside Out 2: Who is the strongest? Joy vs Envy vs Anger #shorts #animation
00:22
Why Is He Unhappy…?
00:26
Alan Chikin Chow
Рет қаралды 47 МЛН
A little girl was shy at her first ballet lesson #shorts
00:35
Fabiosa Animated
Рет қаралды 15 МЛН
Amazing weight loss transformation !! 😱😱
00:24
Tibo InShape
Рет қаралды 62 МЛН
DNS Records Explained
14:14
PowerCert Animated Videos
Рет қаралды 290 М.
DNS Security Overview
1:01:25
Wes Hardaker
Рет қаралды 3,4 М.
DNS Cache Poisoning - Computerphile
11:04
Computerphile
Рет қаралды 301 М.
The moment we stopped understanding AI [AlexNet]
17:38
Welch Labs
Рет қаралды 822 М.
Что такое DNSSEC? Из-за него сломался интернет.
6:59
Мир IT с Антоном Павленко
Рет қаралды 6 М.
Introduction To DNS and DNSSEC
21:34
Tim Rooney
Рет қаралды 62 М.
Understanding How DNS Works in Depth
19:18
ITdvds
Рет қаралды 325 М.
Understanding DNS Zones
36:10
William Panek
Рет қаралды 90 М.
Why Secure DNS is Important
5:51
IBM Technology
Рет қаралды 21 М.
Subnet Mask - Explained
17:55
PowerCert Animated Videos
Рет қаралды 2,7 МЛН
Inside Out 2: Who is the strongest? Joy vs Envy vs Anger #shorts #animation
00:22