4 ms·
This would need DNS to be secured though and DNSSEC is still a bit of a mess last I checked and not enabled for a majority of DNS traffic.
by tscs37 9y ago
This would need DNS to be secured though and DNSSEC is still a bit of a mess last I checked and not enabled for a majority of DNS traffic.
- aeden 9y agoDNSSEC support is increasing each year, but that's just one issue. DANE would also need to be implemented by browsers for full adoption, not just as a plugin to specific browsers. Then again, I was responding to the question about an RFC or other standard, not whether it was feasible today. ;-)
- tscs37 9y agoIt would be feasible if DNSSEC wasn't a total mess, tbh. The support for it is still abysmal and a lot of resolvers (including the one in my router) can't handle DNSSEC responses at all. I think using DNS over HTTPS in conjunction with signing the response is going to be more viable since you don't have 200 ways a middle box will break it.