Skip to content

Comment on Encrypted DNS and NTP = Deadlockparent

Comments

DNSSEC isn't "connectionless"; DNSSEC responses frequently exceed the maximum UDP packet size.

TLS DNS provides confidentiality, in addition to hop-by-hop integrity; DNSSEC provides no integrity, which has led to a decade of rationalizing by its advocates about DNS not "needing" confidentiality.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.