3 ms·
"You need both." Me, personally? I do not use shared caches. I do not use local or remote caches. Wrote own nonrecursive (i.e. no RD bit ever set) stub reso
by aplorbust 9y ago
"You need both."
Me, personally?
I do not use shared caches.
I do not use local or remote caches.
Wrote own nonrecursive (i.e. no RD bit ever set) stub resolver.
As such, I have no use for DNSCrypt.
I use trusted sources for lists of authoritative servers I need. I store IP addresses for those servers permanently and track changes in them, if any, over time.
I have little interest in what ICANN certifies as a "valid" or "invalid" name. DNSSEC therefore does not appeal to me.
IMO, better Web PKI could be focused on IP addresses and user-generated public keys (maybe combined with user-chosen "pet names"), something like SSH. Instead it appears to be solely focused on names issued by a third party and certificates based on those names, also issued by a third party.
Probably "You need both" was a figure of speech. If so, pay no mind.
"can you find that?"
http://cr.yp.to/talks/2016.12.08/slides-djb-20161208-dnssec-a4.pdf http://cr.yp.to/talks/2016.12.08/slides-djb-20161208-dnssec-... and other DNS talks on that page
Pages 11, 32.