Skip to content

Comment on Open Wi-Fi Securityparent

Comments

Against a network-level adversary, DNSSEC does exactly nothing: it's a server-to-server protocol, and the interaction between the resolver on your desktop and the DNS server remains unprotected. And, of course, as you mention, even if you ran a recursive validating resolver on your desktop, DNSSEC still doesn't encrypt anything.

People should simply not bother with DNSSEC.

What do you recommend then? I think DNSCrypt is nice for client-to-server.

Edit: nvm, forgot DoH and DoT were a thing

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.