The Key to the Internet Is a Physical Object

Experts discuss the critical role of DNS security, the risks of cache poisoning, and the importance of the root key-signing key for internet trust.

5 minutes · No politics · Just things worth knowing

Transcript

The website to the signing: https://www.iana.org/dnssec/ceremonies/52

It's Thursday, September tenth. Four times a year, a group of people enters a locked room on each coast of the United States. They open tamper-proof bags, remove physical smart cards from safe deposit boxes they each hold a separate key to, and activate a machine designed to self-destruct if anyone tries to open it. They are there to sign the internet.

Not metaphorically. Every time you type a website into your browser, your computer asks a series of questions: where is this domain? Which server holds it? A chain of answers cascades down from the root of the Domain Name System — the DNS, which is the phonebook of the internet. If someone can hijack that chain, they can redirect you to a fake version of your bank, your email, anything. The defense against this is a cryptographic protocol called DNSSEC, and the entire thing rests on a single digital key. The root key-signing key. If it's compromised, the trust architecture of the internet collapses.

So the question becomes: where do you put the most important key in the world?

When the internet was designed, nobody thought about security. The Domain Name System was built in the early nineteen eighties by Paul Mockapetris, and it had one job: translate human-readable names like google dot com into the numerical IP addresses computers actually use to find each other. It was like a phonebook. You look up a name, you get a number.

The problem is, DNS was built on trust. A DNS server asks another DNS server for an address, and whatever answer comes back, it believes. There was no way to verify that the answer was authentic. If you're sitting in a coffee shop and someone on the same WiFi network answers your computer's DNS query faster than the real server does, your computer will happily accept the fake response. This is called DNS cache poisoning, and it's not theoretical. In two thousand eight, a security researcher named Dan Kaminsky found a flaw that made it almost trivially easy. He spent months coordinating a secret patch across every major tech company on Earth before going public. It was the closest the internet has ever come to a coordinated heart attack.

The permanent fix was DNSSEC — the Domain Name System Security Extensions. The idea is simple. Instead of just accepting whatever answer comes back, your computer checks a cryptographic signature. If the signature is valid, the answer is real. If it's not, your browser throws up a warning. Every layer of DNS signs the layer below it, forming a chain of trust. Dot-com signs the signatures for individual websites. The root zone signs the signatures for dot-com.

And the root zone has no parent. Nothing signs for it. It signs for itself with a single private key — the root key-signing key, or KSK — stored in exactly two places on Earth.

This key has to be physically accessed four times a year to sign the keys that keep the whole system running. And the people who control access to it are not government officials, not ICANN executives, not the NSA. They are volunteers. Fourteen of them, plus seven backup key holders, from twelve countries, who pay for their own flights.

There are two key management facilities. One is in El Segundo, California, just south of Los Angeles. The other is in Culpeper, Virginia — specifically chosen, as ICANN's own briefing notes, because it is "outside the nuclear blast zone of Washington, DC."

The security has seven tiers.

Tier one through four: the data center itself. Guarded, access-controlled, the kind of facility where you hand over government ID and get an escort.

Tier five: a room within the data center, the safe room. To get in, an ICANN staff member needs a retinal scan. Everyone entering signs a log. Nobody enters alone.

Tier six: inside the safe room is a cage. To enter the cage requires two people simultaneously — the Ceremony Administrator and an Internal Witness, each with their own access card and another retinal scan. Neither one can enter alone. This isn't a policy. The door physically won't open without both credentials.

Inside the cage are two safes. The hardware safe holds a Hardware Security Module — a specialized computer roughly the size of a thick book, designed for one purpose: storing cryptographic keys. If anyone attempts to open its casing, the HSM detects the breach and instantly destroys its own contents. The key literally self-destructs.

The credentials safe holds seven safe deposit boxes. Each box requires two physical keys to open. The Ceremony Administrator holds one key for every box. The seven Crypto Officers each hold the second key to a different box. Inside each box is a tamper-evident plastic bag containing a smart card.

The bags matter. At a previous ceremony, someone discovered you could manipulate the smart cards by poking needles through the tamper-evident bags without leaving visible marks. They redesigned the bags. The cards now sit inside hard plastic cases sealed inside the bags. Every detail of this ceremony has been attacked, probed, and hardened across fourteen years and more than sixty ceremonies. The process is not elegant. It is paranoid. That's the point.

The ceremony requires at least seven people in addition to auditors and witnesses. Three Crypto Officers. The Ceremony Administrator. An Internal Witness. A Credentials Safe Controller. A Hardware Safe Controller. And someone else — the Physical Access Control Manager — who isn't even on site, because they control remote access to the room and their absence is a security feature.

Everyone shows up, shows ID, gets escorted in. The Crypto Officers haven't seen their safe deposit boxes in three months. The last person to touch their smart cards was them, at the previous ceremony.

They enter the cage. The Credentials Safe Controller opens the first safe. One by one, each Crypto Officer steps forward with their physical key. They inspect their tamper-evident bag — hold it up to the light, check the seals, confirm the serial number matches what it was when they last placed it here. They hand the bag to the Ceremony Administrator, who is the only person allowed to touch the cards from that point forward.

Then the Hardware Safe Controller opens the second safe. Out comes the HSM. Out comes a laptop that has no hard drive, no battery, and no clock backup battery. The machine cannot store state. The moment it's unplugged, everything in memory vanishes. This is not a precaution. This is the architecture. The laptop was designed to forget.

It boots from a DVD. The time has to be set manually, from a wall clock in the ceremony room — the same physical clock installed for the first ceremony in June two thousand ten. It's drifted slightly over the years. That's fine. It's only used for logging. The clock has never been connected to anything. It hangs on a wall and ticks.

The Ceremony Administrator inserts three smart cards into the HSM to activate it, connects the HSM to the laptop via ethernet, and the air-gapped system is live. Nothing in that room talks to the internet. The key-signing request — a bundle of zone-signing keys that Verisign will use for the next quarter — arrives on a USB drive. Someone computes a cryptographic hash of the file. Verisign confirms over the livestream that the hash matches what they sent. The file has not been tampered with.

Then the Ceremony Administrator types a single letter: Y.

The HSM signs the keys. The whole thing takes about four hours, most of which is verification, logging, checking, re-checking. Three cameras record everything. A Big Four accounting firm audits the proceedings. The video, the annotated script, the logs — all of it goes online. You can watch ceremony number fifty-two right now on iana dot org slash dnssec. Nothing is secret. The trust doesn't come from hiding anything. It comes from showing everything.

The system is designed for the catastrophe scenarios.

The Crypto Officers can only activate the HSM. They cannot reconstitute the key if the HSM is destroyed. For that, there are seven Recovery Key Share Holders. Each holds a fragment of the master encryption key on a smart card. If both facilities — Culpeper and El Segundo — are simultaneously destroyed, the key can be rebuilt by bringing together five of the seven Recovery Key Share Holders plus one encrypted backup smart card held by ICANN.

The specification literally says: if both key management facilities fall into the ocean, gather five of seven RKSHs and reconstitute the KSK in a new HSM.

There is also an emergency procedure for when things go wrong faster than people can travel. If a crisis demands immediate access to the key, ICANN staff can drill into the safe deposit boxes, rip open the tamper-evident bags, and activate the HSM without any Crypto Officers present. The protocol acknowledges this as a valid emergency path. But the community would know. The broken boxes, the destroyed seals, the drill marks — all of it would be disclosed. Trust is the product, and transparency is how you prove you haven't broken it.

The designers calculated the collusion risk formally. Their model assumes a five percent dishonesty rate among the participants. With the number of independent conspirators required to compromise the key across multiple roles, the probability of successful collusion was computed at less than one in a million. That's not a metaphor. That number is in the specification.

The first ceremony was on June sixteenth, two thousand ten. Thirty people in a small room in Culpeper for seven hours. No laptops were allowed. The root key was generated that day — a twenty-forty-eight-bit RSA key — and it secured the internet's trust anchor until October two thousand eighteen, when the first-ever key rollover occurred. The current key was generated on October twenty-seventh, two thousand sixteen, and entered production in February two thousand seventeen. The next ceremony — number sixty-three — is scheduled for November twelfth of this year. They will sign the keys for the first quarter of twenty twenty-seven.

There is something quietly astonishing about this arrangement. The digital world runs on a physical key, stored in a physical safe, activated by physical smart cards held by volunteers who fly themselves to Virginia or Los Angeles four times a year and inspect tamper-evident bags under fluorescent lights while three cameras stream the whole thing to anyone who cares to watch.

The internet is not held together by servers and fiber alone. It is held together by the belief that a room in Culpeper has not been breached, that a wall clock has kept ticking, that seven people spread across different continents still have their smart cards in their possession and have not been compromised. Every DNS query you have ever made — every website you have ever visited — has ultimately relied on the fact that nobody has managed to get three of the right people into the same room with the wrong intentions.

The system works because nobody trusts any single person. Not ICANN. Not Verisign. Not the US government — whose commerce department was explicitly excluded from the pool of eligible key holders. The trust is distributed across fourteen volunteers from a dozen countries who hold physical keys to safe deposit boxes and who, once a quarter, put them in a bag, get on a plane, and perform a ritual that is equal parts cryptography, theater, and faith.

Stay informed, stay curious, and we'll see you tomorrow.

Prefer your podcast app?

Or wherever else you get your podcasts.

☕ Get today's briefing in your inbox

5 minutes every morning. Interesting things happening in the world — not politics. Unsubscribe any time.

Want streak tracking and saved preferences?