Passing the Torch – My Last Root DNSSEC KSK Ceremony as Crypto Officer 4
19 points
1 hour ago
| 1 comment
| technotes.seastrom.com
| HN
shruubi
23 minutes ago
[-]
Not sure how geographically diverse it is to have two "highly secure sites" on the same continent.
reply
ggm
6 minutes ago
[-]
Several people either in this circuit or close by made submissions to this effect to ICANN recently.

It's very hard to get traction on this story because there is a lot of "don't prod the bear" regarding things ICANN can and should ask Department of State about, and things which really have moved into "self managed, independent international body" space. The reason there are two HSM east and west coast was because of this kind of national-strategic sensitivity. It would be a low bar (only money) decision to duplicate the investment in Singapore and Geneva, two locations which ICANN has existing investment in, with good secure facilities and accepted by the wider public as "neutral" points.

When the KSK ceremonies started up, several people also pointed out that this "diverse locations" thing was a bit hokey. The response above is my re-write of the kinds of things said to me, at the time. If somebody wants to deny State or any other US federal agency influenced the decision I have no formal proof.

I should add as a declaration of interest I was at Rob's goodbye KSK event, I am a TCR, and I made such a submission. I have not received any indication it was understood or read, despite asking for some acknowledgement, but the process wheels in an agency like ICANN run to their own time.

reply
tptacek
2 minutes ago
[-]
What would "poking the bear" do here? What's the risk?
reply