Hacker Read top | best | new | newcomments | leaders | about | bookmarklet login

DNSSEC is as secure as SMS.


sort by: page size:

DNSSEC?

DNSSEC?

DNSSEC: it's secure as long as you don't trust the DNS hierarchy.

DNSSEC provides authenticity, not confidentiality.

DNSSEC is also trivial to MITM.

You mean DNSSEC

Use DNSSEC.

DNSSEC

Actually Google's DNS over HTTPS API is used, so it is encrypted and also secured using DNSSEC.

DNSSEC doesn't help privacy, it helps security.

Uh, DNSSEC is only signatures, it has no encryption.

Oh! I always thought DNSSEC was encrypted, thanks for the correction

DNSSEC is signed, not encrypted.

DNSSEC adoption would prevent a hijacker from manipulating responses.

As someone not very knowledgable about DNSSEC, can you expand on this point? To the uninformed that sounds very counterintuitive.

Just like everything else, hence DNSSEC.

AFAIK DNSSec has no additional identity requirements compared to normal DNS.

Any interest in implementing DNSCrypt? I feel DNSSEC alone is useless since one can't guarantee integrity to the DNS resolver.

Except DNSSEC accomplishes nothing really. It does not make anything more secure. Crypto is not a panacea to the problems of trust.
next

Legal | privacy