Hacker News new | ask | show | jobs
by danyork 4427 days ago
I guess we'll have to agree to disagree. I've worked with the ICANN DNS people enough and am aware of their practices enough (ex. https://www.iana.org/dnssec/icann-dps.txt ) that I don't see how the root zone could be compromised without people knowing.

Separately, DNScurve is interesting, but really solves a different problem than DNSSEC. I find this a useful comparison: http://security.stackexchange.com/questions/45770/if-dnssec-...