Skip to content

Comment on Why not DANE in browsersparent

Comments

If traffic is end-to-end protected with cryptography --- as, for instance, it is in the SSH protocol --- why does it matter if DNS records are authenticated? If you forge a DNS record, the SSH protocol will kill the session. SSH doesn't even need to care what the DNS says; all that matters are the cryptographic secrets.

I'm going to be generous here and assume they meant authenticated encryption rather than just encryption between the user and the first DNS server they hit.

Which, given how DNSCurve was designed, is a non sequitur :)

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.