|
|
|
|
|
by growse
1339 days ago
|
|
The owner of com. (which is effectively the US govt) can hand out whatever records it likes for anything under .com. All DNSSEC gives you is a false sense of security as you merrily validate signatures on spoofed records because they're generated by the same people who own the DS record responses. And what happens when you (and everyone else) finds out you can no longer trust DNSSEC signatures on .com.? Stop using all of .com? > but the power lies with the configuration of a device's DNS resolver. Any recursive resolver is free to configure other root servers (e.g. OpenNIC). How does OpenNIC know how to answer the question "where is ycombinator.com"? |
|
As opposed to the current system, which also gives you a false sense of security while being vulnerable to exactly the same .COM attack, but also to even more types of attacks?