Tamper-Evident
Abstract
The internet's root master key changes hands on October 11, 2026 โ the second rollover in history, booked on the same calendar date as the first. Eighteenth in the custody series: the ICANN key ceremonies as custody of consent, tamper-evident by design and boring on purpose โ two coasts, two safes, fourteen officers in rotation, a thirty-page script read aloud. The key itself took eighteen seconds to make, inside an eight-hour liturgy.
Eighteenth in the custody series.
1.
The address is public. 18155 Technology Drive, Culpeper, Virginia โ printed on IANA's own help page for key-ceremony attendance, next to a recommended hotel. The room where the internet's master key is kept is not hidden. That is the design, in miniature. Nothing in this custody depends on secrecy; everything depends on witnessed access.
Past the front door, the choreography is spatial. A ceremony room under a two-person rule. Inside it, a metal cage โ the safe room, also two-person. Two safes stand there. The first holds the machines: hardware security modules, each sealed in a tamper-evident bag, and two laptops built so they cannot betray โ no Wi-Fi, no Bluetooth, no battery, no storage, never networked, their operating system carried in on a DVD for each ceremony, their clocks set by hand. Beside them, a smartcard holding the encrypted backup of the key. The second safe holds no machines at all, only safe-deposit boxes, each under two keys โ one IANA's, one a Crypto Officer's โ so that no one person, alone, can reach anything that matters.
The whole room is a thesis. LACNIC's chief technology officer โ himself one of the fourteen Crypto Officers โ called it, from inside, "a very physical and material process to certify the health and safety of digital life." The security is not that no one can touch the key. It is that every touch leaves a record, and every record is published.
2.
The first ceremony ran about eight hours. The key itself took eighteen seconds.
The log survives, verbatim. 21:19:06, the key-generation program starts; ten seconds on, the hardware module โ an AEP Networks Keyper Pro 0405, serial K6002013 โ is activated, and the line runs: "Generating 2048 bit RSA keypair..." And at 21:19:24: "Created keypair labeled 'Kjqmt7v.'" Inside an eight-hour liturgy, the birth of the root of trust occupied less than half a minute of it.
The certificate's common name is the instant of its birth: Root Zone KSK 2010-06-16T21:19:24+00:00. A key that cannot lie about when it was made. And because humans cannot check a hexadecimal digest by eye, it is also spelled in the PGP word list โ deckhand, pedigree, snapline, breakaway, kickoff, hemisphere, flytrap, detergent โ thirty-two English words in a row no one chose: the master key's true name as a found poem.
Key tag 19036. A month later, on July 12, a second facility in El Segundo, California imported the same key. Two coasts, one truth. And from that summer on, the ceremonies settled into their real work: every quarter, in advance, they pre-sign the next quarter of the internet. The near future of the network lives in safes in Virginia and California until it becomes the present.
3.
The ceremony has a script, about thirty pages, and the script is read aloud. The Ceremony Administrator reads; the participants follow; the Internal Witness timestamps every step and records every deviation โ the ritual's word is "exceptions," and they are routine, logged as a matter of course. A Crypto Officer of two years' standing has written of his surprise at a ceremony with none. Exceptions are expected the way weather is expected.
The liturgy binds each ceremony to the last. The tamper-evident bags come out and their serial numbers are matched against the previous ceremony's records. Three Crypto Officers present their smartcards to wake the signing module. A Verisign representative reads the hash of the zone-signing key aloud from his own papers, against the display of the disconnected laptop, and the Ceremony Administrator types y. Five copies are made of the audit log. At the end, every participant signs the Internal Witness's annotated script, and it is filed with the rest: three cameras' footage, the signing logs, the ceremony materials โ down to the signing computer's operating system, published as a hash-verified ISO. The ritual publishes its own instruments. "The purpose is to ensure trust in the process," ICANN says.
It is boring on purpose, and filmed so that it can be trusted without being watched. This is the title's word at work. Nothing in that room is tamper-proof. The bags do not prevent opening; they record it. The seals, the signatures, the cameras, the matched serial numbers โ the entire apparatus is tamper-evident. In this series, once before, the public record was the thing itself. Here it is again: the record is not about the custody. It is the custody.
4.
The world met the cast as myth. ABC News, July 2010: "Tolkien had his rings of power, King Arthur his round table, and now, the Internet has its own answer." Seven keyholders โ the Recovery Key Share Holders โ of whom five would "meet in one physical location" to restore the system after a catastrophe. The press improved the story as it traveled; a widely syndicated 2014 feature had the fourteen primary keyholders opening, each with a metal key, a safe-deposit box "which in turn contains a smartcard, which in turn activates a machine that creates a new master key" โ in a room that meets four times a year. They generate nothing. The ceremonies pre-sign. In sixteen years the master key has been generated four times โ 2010, 2017, and twice more in 2023โ24, one of which has never been trusted at all.
The custodians disputed their own dramatization in public. APNIC's Cameron Steel called the myth-making "disingenuous at best": a Crypto Officer's key opens nothing outside an unlocked safe in a locked cage in a witnessed room, and even five of the seven conspiring Recovery Key Share Holders could reconstruct only the storage key that guards the backups โ and would hold, still, nothing. LACNIC answered from the other pole, in the title of its own essay: "A Theatrical Plot and a Secret Key." The process, its chief technology officer wrote, "borders on the theatrical" and has "already become an Internet myth" โ and he smiles at being called one of the Internet's notaries. Both poles describe the same mechanism. The theater is not a cost of the custody. It is the custody.
One holder made the myth quietly true. Dan Kaminsky, who found the DNS cache-poisoning flaw of 2008, served from 2010 as one of the seven, and was still one when he died, in April 2021. The roster needs no decoration: the era's most famous flaw, and its finder died holding one of the seven shares of the key that guards the master's backup.
5.
The key was ready before the world was. The stated objective for the key's operational lifetime is "nominally five years"; the first key served eight. The constraint was never the object. It was the installed base of trust: a resolver that has never seen the new key cannot simply be told. Under RFC 5011 it must observe the new key in "at least two validated DNSKEY RRSets," then hold its judgment for thirty days before believing. Trust, mechanically, is a month of seeing.
The first rollover was booked for October 11, 2017. Two weeks before the date, it was postponed โ "a significant number of resolvers ... are not yet ready," the announcement said; ICANN's later summary called it "confusing signals" in the root server system. The key had been generated in the ceremony room; the world's software hadn't finished looking at it. The custodians waited a year for the trusters, and on October 11, 2018, the master key of the internet changed for the first time in history. Not because the key had improved. Because enough of the world had, finally, seen it twice.
And because guessing had failed once, the community built instruments to ask: resolvers now report their trusted key tags upward, and specially-labeled questions are posed whose answers depend on which key the asker's resolver trusts, so the installed base can be polled instead of supposed.
6.
February 2020, ceremony forty. The safe locks had been discontinued by their manufacturer; both were to be replaced. One replacement went cleanly. The other lock accepted its code and would not open. The manufacturer's indicated remedy was drilling โ the instructions public, the locksmith certified โ and what was "initially meant to be a matter of a few hours" turned out to be a two-day event. Three of the technical-community representatives stayed the extra days; the ceremony ran on a Saturday evening; optional steps were skipped; one participant caught his postponed flight to a conference in Melbourne. The quarter's signatures were already in the pipeline, signed the quarter before. The schedule is designed to bend: the buffer of pre-signed material exists precisely so the ritual can fail to run on time without the internet noticing.
Then the pandemic. Ceremonies forty-one and forty-two ran remote: the Crypto Officers couriered their safe-deposit-box keys to IANA in tamper-evident bags and granted their permission over video, and each sitting generated nine months of signatures โ three quarters of the internet pre-signed in one witnessed sitting. The ritual bent without breaking, and the bending itself was witnessed, bagged, and logged.
7.
April 2023. The manufacturer of the hardware modules announced it would exit the business โ "during the expected lifespan of the new KSK," as the record puts it. The key's crib would die before the key did.
The rollover was already underway. A new key โ KSK-2023 โ had been generated in the ceremony room and replicated to both coasts. Now it was held. IANA's posting that July is a museum piece of institutional conditionality: "There is a strong likelihood we will seek to generate a new KSK on a new HSM platform once operationalized, which will cause us to abandon the recently generated KSK. We will however retain the recently generated KSK for now should those plans not pan out."
So there is a key that was born in the room, replicated to two coasts, never trusted by a single resolver, and kept anyway โ a spare for a plan that might fail. It was superseded the following April by KSK-2024, generated on hardware chosen to outlive it, which then waited more than two years for its turn. In parallel, another track designs the rollover of the algorithm itself: RSA's eventual death already has a committee.
8.
In the weeks before the second rollover in history, the instruments disagree.
The resolvers' own reports โ RFC 8145, resolvers signaling their trusted key tags to the root servers โ read, by March 2025, that about ninety percent of reporting resolvers carried the new key. The jump landed thirty days after the key entered the root's DNSKEY set in January 2025, exactly as RFC 5011 draws it. A later snapshot, from ICANN in July 2026, reads above ninety-five percent of reporting resolvers โ same instrument, later window. Both of those measure machines that volunteer the answer.
The other instrument measures people. RFC 8509's sentinel method puts its questions inside ordinary lookups and watches end users' traffic answer them: in April 2026, under twenty percent of users behind validating resolvers had the new key. "This is certainly not the result that we had anticipated," wrote Huston, who runs the measurement, in May. Three numbers, three populations, three instruments; none of them collapse into "the internet is ready" or "it is not."
And the ghosts: half a percent of resolvers, measured in 2025, still trusted KSK-2010 โ revoked six years, deleted from the ledger across two ceremonies, alive anyway inside un-updated software images. Dead keys linger the way dead languages do, in artifacts no one re-reads. Even the measurement itself is forensics: the sentinel's probe questions defeat wildcard TLS certificates, so the instrument must read its handshakes in the clear.
October 11, 2026 โ the calendar date the institution has now chosen three times โ key tag 38696 becomes the root's sole signing key. ICANN's stake, verbatim: unprepared resolvers will "experience total DNS resolution failures, cutting off Internet access." The system's answer to not knowing is its oldest one: the buffer, and failure that is loud.
9.
The ending is booked, and it is not an ending. KSK-2017 โ the current key, in its eighth year โ has its deletion scheduled for April 2027, a line item on the published ledger of ceremonies, which books the generation of its successor, KSK-2027, for the very next day. Death here is as ritualized as birth: the module's tamper mechanism triggered by hand, the device disassembled, its sensitive components sealed in a bag and dispatched to a third party for shredding. The custody does not conclude. It rolls.
The kilogram's duty, elsewhere in this series, succeeded out of existence. The waste site's message asked to be replaced when it became hard to read. This custody pre-empts the question: it replaces itself on a calendar, on purpose, so that nothing has time to harden. What is kept, quarter after quarter, is not the key โ one key destroyed, one never trusted, another queued for the shredder โ but the consent: the world's standing agreement to treat a particular 2,048 bits as truth, re-manufactured on schedule by fourteen officers in rotation and a thirty-page script, in a room whose address you can look up, next to the Holiday Inn Express the help page recommends.
Nothing in the room is tamper-proof. Nothing needs to be. At the published address, bagged, witnessed, signed, and boring, the internet keeps the next quarter of itself โ which is the sound of it working.