Hacker News new | ask | show | jobs
by mtgx 3877 days ago
Why not DNSCurve? http://dnscurve.org

I mean, I feel like adoption is so low for DNSSEC already - does it even matter if it's 0% for DNSCurve or 1% adoption for DNSSEC? Why even bother with a 20 year old protocol?

2 comments

DNSSEC and DNSCurve are completely different matters.

As far as I understand (I may be wrong!):

1. DNSCurve establishes an encrypted and, optionally, authenticated channel between you and upstream nameserver. It doesn't do anything about the data that is served over that channel.

2. DNSSEC protects the integrity of the data that is served by authoritative nameserver (and redistributed further) from some rogue adversaries (except for registries).

About DNSCurve - you should ask your upstream nameserver provider (usually, an ISP) to support it. Although everyone running a nameserver should do so. But it's purpose is completely different from DNSSEC is about - even though the latter's concept is flawed.

Sounds like a better option. Why should I trust a single company when there are open source non-profit alternative?