Dan Kaminsky told me about the signing ceremony years ago (bless his heart, he was one of the people trusted with DNS security). Apparently, everyone on the signing committee flies to a central location carrying a hardware key. Then they take turns inserting their hardware key into a hardware security module. It's all done face-to-face because that's the only way to guarantee that human consent was granted properly at each step.
The whole thing is performative (it's why the people with the key shares had them: to generate publicity for DNSSEC). The root keys could wind up on Pastebin tonight and almost nobody in the world would need to be paged.
Dan Kaminsky told me about the signing ceremony years ago (bless his heart, he was one of the people trusted with DNS security). Apparently, everyone on the signing committee flies to a central location carrying a hardware key. Then they take turns inserting their hardware key into a hardware security module. It's all done face-to-face because that's the only way to guarantee that human consent was granted properly at each step.
Each ceremony is recorded on video and distributed to the public. The last one was in August, 2026: https://www.youtube.com/watch?v=-QqYS3oLfL8&t=1s
The whole thing is performative (it's why the people with the key shares had them: to generate publicity for DNSSEC). The root keys could wind up on Pastebin tonight and almost nobody in the world would need to be paged.
I'm requesting David's, Ellis's, and Adam's from Waveform: MKBHD Podcast attendance.
Context: https://www.youtube.com/watch?v=26WvISI14g0