3 ms·
I've been reading up on this recently, and I've seen a few articles on DNSSEC vs DNSCurve, how would you weigh in?
by pcnix 9y ago
I've been reading up on this recently, and I've seen a few articles on DNSSEC vs DNSCurve, how would you weigh in?
- akvadrako 9y agoBoth are irrelevant in practice, but DNSSEC is de facto standard; it's what the root servers implement.
- sybercecurity 9y agoDNSSEC (IETF standard) only provides authentication and integrity protection. DNSCurve can also provide confidentiality. DNSCurve does require the authoritative server to do crypto on the fly, so may require a lot more work for the root/TLD servers. DNSSEC is just signed DNS data, so the work can be done offline. So operators just do DNSSEC, very few operators deploy DNSCurve. Actually, most places do neither. There is the possibility to mix the two - use DNSSEC for root/TLD servers and then DNSCurve on the lower level or leaf zones. It would be hard to know when to switch over from DNSSEC to DNSCurve(other than try at the 2nd level and below). Query minimization may help in privacy protection at the root/TLD level.