|
|
|
|
|
by bluejekyll
1721 days ago
|
|
I'm not going to defend DNSSEC here, because this outage and others continue to support tptacek's perspective on its usefulness. But, some governments are requiring DNSSEC, which regardless of its usefulness, puts companies that want those contracts in a bit of a bind. Perhaps it would make sense to split domains such that DNSSEC guarded ones would not negatively impact ones that do not have DNSSEC. |
|
The important top-line thing to know here is that virtually all tech companies eschew DNSSEC (you can verify that for yourself with `host -t ds stripe.com`; substitute any other company for Stripe.
DNSSEC-quarantine TLDs are a good idea.