3 ms·
Just like you can f* up HTTPS when you have Strict Transport Security, you can f* up DNSSEC. While I don't really like current DNSSEC implementations, this is
by dcbadacd 7y ago
Just like you can f* up HTTPS when you have Strict Transport Security, you can f* up DNSSEC. While I don't really like current DNSSEC implementations, this is not DNSSEC's fault really. The idea I do like, that recursive resolvers can't tamper my resolving - that the recursive resolver is left out of the trust chain.