5 ms·
DNSSEC is dead and useless unless every application is written to understand the error messages and every device runs its own DNS resolver (not forwarding, beca
by feld 9y ago
DNSSEC is dead and useless unless every application is written to understand the error messages and every device runs its own DNS resolver (not forwarding, because it's not really validating then and the responses could be spoofed).
We don't need DNSSEC because it doesn't solve any existing problems. The validation is done at the application protocol level with TLS, and apps that aren't running TLS need to fix this gap.
So as it turns out DNSCrypt is winning the internet even though the standards bodies blocked it. Additionally, OpenDNS has massive deployment of DNSCrypt users and this is being furthered by Cisco Umbrella. Cisco is adding this capability to iPhones now as announced earlier this week.
tl;dr DNSSEC has always been DOA, but DNSCrypt is just getting started.
The one and only application I knew of that added DNSSEC for DANE removed it because it was worthless (irssi, irc client).