|
|
|
|
|
by nly
4163 days ago
|
|
The objective is to leverage DNSSEC to prevent downgrade attacks. Whether or not you are connecting to a host over HTTP or HTTPS you need to query DNS, which makes it an ideal place to introduce a message to clients to tell them what they should be doing. In an ideal world, a DNSSEC enabled recursive resolver, querying a domain name under a DNSSEC-enabled TLD, should not be fooled to downgrade. |
|
So again: what's the point? Compared to HSTS headers, DNSSEC is incredibly expensive.