3 ms·
So does this render DNSSEC effectively moot? It's not much good for authentication if the government can change the authoritative name servers for any .com/.or
by incant 16y ago
So does this render DNSSEC effectively moot? It's not much good for authentication if the government can change the authoritative name servers for any .com/.org/.net domain and then sign that change.
But perhaps I don't understand how DNSSEC works. It seems unlikely that its designers would ignore that concern.
Edit: Or were they only concerned cache poisoning? There's been much talk of using DNSSEC to authenticate websites and even people. If I'm understanding DNSSEC correctly, it seems terribly misguided, even worse than the idea of "government key escrow".
- marshray 16y agoMy understanding is that DNSSEC neither helps nor hurts in this scenario. It mainly enforces the accuracy of the registration database, which in this case is being modified at the request of DHS.