Skip to content
A chain of trust running from the signed root through a signed TLD and stopping at an unsigned second-level domain, with the counted figures beside each step

DNSSEC: Protecting Your Traffic From Forgery

The hard part of DNSSEC was finished years ago. Counted from the live root zone on 27 September 2026, 1,351 of 1,438 top level domains carry a DS record and every one of the 1,038 gTLDs is signed. Then it stops dead. A census of every gov.uk domain in the official register finds 39 signed out of 2,390 that still resolve, nine of them parish councils, while HMRC, the NHS, GCHQ and the National Cyber Security Centre are not among them. One certificate authority in nine has signed. So has one Linux distribution in three. windowsupdate.com has no DS at all. This is what a forged answer actually costs, what signing does about it, why the usual excuses do not survive contact with the numbers, and whether forty-two years after Mockapetris the real problem is that almost nobody understands what DNS actually promises.

27th September 2026 Â· 48 min Â· 10979 words Â· Damien Dye

DNS Over HTTPS Walks Straight Past Your Controls

DNS over HTTPS encrypts your lookups, which is good, and sends them to a resolver of the client’s choosing on port 443, which is the problem. Your own resolver never sees the query, so the blocklist it would have failed, the threat feed it would have hit and the log line it would have written all vanish. This post walks the mechanism: why one encrypted web connection among thousands is invisible at the border, who on a machine can pick a resolver you never chose (the OS, the browser, any app, any script on any web page, and malware), and the documented cases, from a page’s own JavaScript querying a public DoH endpoint that allows cross-origin requests, to Godlua and PsiXBot hiding their command channel inside DoH, to the OilRig APT exfiltrating data over it. Then the case that the privacy story is a cover: DNS over TLS already encrypted DNS in 2016, on a port the network operator can still govern, so the only thing DoH adds over it is defeating the admin, which is why the browser vendors who wrote and shipped it, and the advertising firm that runs the biggest public DoH resolver, are the ones who gained. Then the fix, which is not to ban encryption. Run your own DoH and DoT resolver, advertise it with Discovery of Designated Resolvers, refuse port 53, port 853 and known public DoH resolvers at the border, and answer the Firefox canary so the browser stands down. Keep the encryption. Take back who chooses the resolver. It closes on the fallout: the same DNS-based enforcement runs across Europe and in Australia, and courts in Italy, France, Belgium and Germany are now ordering the public resolvers themselves to block, with Cloudflare fined and appealing, Google refusing in silence and OpenDNS switching itself off for whole countries. The pattern underneath is a US design imposed on the world, and a US government that casts other countries’ laws as extortion of American firms and warns them not to comply.

24th September 2026 Â· 38 min Â· 9567 words Â· Damien Dye

Your Firewall Takes Instructions From Strangers. Turn Off the Protocol Helpers.

A protocol helper — SIP ALG, FTP helper, H.323 ALG, conntrack helper, call it what your vendor calls it — reads the payload of a connection, finds an address and a port written in the text, and opens an inbound pinhole for them. It cannot tell whether that text came from a real FTP client or from a hidden form on a web page, because there is nothing in it to tell. Samy Kamkar proved the browser case in 2010. NAT Slipstreaming proved it again in 2020, and Armis extended it in 2021 to reach any device on your network, not just the machine that clicked. The IETF asked for these off by default in 2007, Linux turned them off in 2016, and the browser vendors ended up shipping a blocked-port list that reads like a directory of conntrack modules. This post walks the mechanism diagram by diagram — the expectation table, the segment-alignment trick, H.323 call forwarding, the IRC helper that fires on somebody else’s message — takes in the IPsec pass-through helper, which cannot read ESP at all and steers inbound packets on an SPI it watched go past in the clear, sets the lot against the Cyber Essentials firewall control it plainly fails, and gives the commands to turn it all off on Linux, Cisco, Juniper, FortiGate and MikroTik.

14th September 2026 Â· 54 min Â· 12564 words Â· Damien Dye

What Your MSP Built You, And Who Else Can Reach It

Part 2 of 3. What actually gets built once the paperwork is signed: cloud for a business with one building, the box they will not be talked out of, the basics that were the thing you bought, and the agent on every machine that answers to somebody else’s console.

28th August 2026 Â· 39 min Â· 8289 words Â· Damien Dye

Backdoors, and Who Gets Accused of Them

Shutting a supplier out on security grounds needs a standard, applied evenly. Part 6 of 8 sets out what has been established about weakened products and interception, including a Swiss parliamentary inquiry, and shows why a built-in way in belongs to whoever reaches it.

25th August 2026 Â· 6 min Â· 1099 words Â· Damien Dye
A delegation chain from the root down to an internal Active Directory zone, with client writes confined to a separate sub-zone

Samba4 and Securing AD Records Using DNSSEC

Every domain-joined machine finds its domain controller by asking DNS for an SRV record, so the _msdcs locators are the most security-critical records you own. This is how to publish and sign them properly from a Samba4 DC: BIND with dlz_bind9 reading the directory, inline signing, a hidden primary that clients never reach, and client dynamic updates kept out of the zone that holds the locators. Then how to force Windows and Linux clients to actually check the signatures, because a signed zone nobody validates behaves exactly like an unsigned one.

24th August 2026 Â· 65 min Â· 13681 words Â· Damien Dye