cowickindustrials.co.uk

DNSSEC key placed in a TXT record, breaking the chain of trust

$ dig TXT cowickindustrials.co.uk

;; QUESTION SECTION:

;cowickindustrials.co.uk. IN TXT


;; ANSWER SECTION:

cowickindustrials.co.uk. 3600 IN TXT "257 3 13 a9e69353dd4a531a76852b847a1847b2df0703fee47e42950e9bfef27edfdd9e99417f09c864b2948879d613bffe6cffcb57f3796443b082c2e025c75fdcef45."

The `257 3 13` prefix is unmistakable: this is a DNSKEY record (DNSSEC cryptographic signing key using ECDSA Curve P-256). The admin pasted their highly sensitive DNSSEC key directly into an unencrypted TXT record instead of the DNSKEY record type. This completely breaks DNSSEC's chain of trust and exposes the signing key to any DNS observer.

257 3 13 a9e69353dd4a531a76852b847a1847b2df0703fee47e42950e9bfef27edfdd9e99417f09c864b2948879d613bffe6cffcb57f3796443b082c2e025c75fdcef45.