Hacker News really sucks for quoted point-by-point responses. I don't think that's an accident. Try writing standalone comments.
After more than 13 years of failed attempts to secure the DNS, you need to better than "we haven't actually tried it yet". DNSSEC enthusiasts could have made the same argument 8-9 years ago with the "original" DNSSEC protocol, which ended up being scrapped.
Meanwhile, the operational problems DNSSEC will cause are, I think, entirely relevant to DNSSEC's role in web security --- both because of the weaknesses in DNSSEC that would directly impact its utility as a CA (for instance, the role of stub resolvers), and because of the damage it could inflict on the rest of the stack.
Comments
Hacker News really sucks for quoted point-by-point responses. I don't think that's an accident. Try writing standalone comments.
After more than 13 years of failed attempts to secure the DNS, you need to better than "we haven't actually tried it yet". DNSSEC enthusiasts could have made the same argument 8-9 years ago with the "original" DNSSEC protocol, which ended up being scrapped.
Meanwhile, the operational problems DNSSEC will cause are, I think, entirely relevant to DNSSEC's role in web security --- both because of the weaknesses in DNSSEC that would directly impact its utility as a CA (for instance, the role of stub resolvers), and because of the damage it could inflict on the rest of the stack.