4 ms·
DNSSEC support is increasing each year, but that's just one issue. DANE would also need to be implemented by browsers for full adoption, not just as a plugin to
by aeden 9y ago
DNSSEC support is increasing each year, but that's just one issue. DANE would also need to be implemented by browsers for full adoption, not just as a plugin to specific browsers.
Then again, I was responding to the question about an RFC or other standard, not whether it was feasible today. ;-)
- tscs37 9y agoIt would be feasible if DNSSEC wasn't a total mess, tbh. The support for it is still abysmal and a lot of resolvers (including the one in my router) can't handle DNSSEC responses at all. I think using DNS over HTTPS in conjunction with signing the response is going to be more viable since you don't have 200 ways a middle box will break it.