Skip to content

Comment on Getting Started with DNS over HTTPS on Firefoxparent

Comments

You can make your resolver verify the entire chain.

There are tlds that are unsigned, and any domains that are unsigned. You can not verify the entire chain, because it is possible that the domain you are looking up is infact unsigned. You can maybe pin some of the tld keys, but you can't pin all the domains under them.

You can not verify the entire chain, because it is possible that the domain you are looking up is infact unsigned.

Then you conclude that it's okay that the domain is unsigned. Else - hard fail.

I don't know what the figures are today, but in 2016, 89% of TLDS were signed using DNSSEC - https://www.internetsociety.org/blog/2017/01/state-of-dnssec...

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.