Hacker News new | ask | show | jobs
by Fnoord 876 days ago
IIRC the protocol is also a nightmare for potential reflection DDoS attacks.

Also, the security chain is top-down, from owner of the TLD to the domain to the resolver to the client. With DNS over TLS and DNSCurve, you have it the other way around.