Hacker News new | ask | show | jobs
by tptacek 26 days ago
At this point, with this microscopic level of adoption and this track record of instability, and given that we're now 4 major revisions (all premised on the same original service model that TIS came up with in the mid-1990s), it would make a lot more sense to go back to the drawing board.

That's basically what we did with DoH, a protocol that has drastically more deployment than DNSSEC and a more coherent threat model.

The simplest and most obvious thing you could do, if you were being parsimonious about it, would be to switch to an online-signer model. With modern (circa 2005) cryptography, you'd do a straightforward client/server authenticated denial without any of the record-chaining silliness. A big chunk of the complexity of the protocol would just vanish.