2 ms·
End to end DNSSEC deployment would prevent an attack like this once clients are rejecting any unsigned records. At least in addition to the root name servers th
by trotsky 16y ago
End to end DNSSEC deployment would prevent an attack like this once clients are rejecting any unsigned records. At least in addition to the root name servers the seizing party would need to convince the TLD maintainer and the customer's registrar to sign the new zone files.
All the more reason for you to sign your current zones (including .org, .info, .us and .eu) or pressure your registrar and TLD maintainers to implement DNSSEC yesterday.