Hacker News new | ask | show | jobs
by tptacek 2690 days ago
DNSSEC does little to prevent state-level intercept of DNS queries, since it's a server-to-server protocol that collapses down to a single, trivially-flipped header bit in the client/server transaction.