Skip to content

Comment on Why not DANE in browsers

Comments

The fact that TXT records don't work for some people shouldn't stop us. Anything that isn't currently widely used is broken for lots of people, because that's how networks are administered. Once it gets deployed and people start complaining, any specific network problem will get fixed.

Delaying proper network security because it won't currently work for a few percent of people seems like a recipe for never getting there.

It's a cost-benefit issue. Do you believe DNSSEC is so valuable that it's worth (a) breaking connectivity for a significant number of people and (b) incurring the expense of replacing/upgrading the middleboxes that are breaking connectivity? If so, why?

I don't have a strong opinion on DNSSEC itself. It seems like it might be a good idea for email, at least.

I don't have much sympathy for network admins who block TXT records because it doesn't currently seem to break anything. TXT records are part of the spec, and if some of them have configured something to block them, that's not a good reason for everyone to not have secure systems.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.