Hacker News new | ask | show | jobs
by bluejekyll 3368 days ago
Sure. But who's running every node in the DNSCrypt graph? I've never been clear about what that looks like.

I still see DNSSec as providing value before the entire graph of DNSCrypt or DNSoverTLS exists.

1 comments

There isn't one DNSCrypt graph. It's a forest of graphs that, in the event DNSCrypt became mainstream, would effectively converge. But, unlike DNSSEC, DNSCrypt doesn't require universal adoption to provide value.

DNSSEC provides no value at all until graph coverage is reached, and even then provides absolutely no privacy.