Skip to content

Comment on Why not DANE in browsersparent

Comments

3) merely requires you can authenticate the DNS response, if I'm not mistaken; DNSCurve would work just as well there as a result.

While adoption of DNSCurve would of course be wonderful for privacy online, it cannot be used right now to provide DNS record authentication. The root and TLD nameservers would need to enable support for it, otherwise you'll always be able to MITM the upstream NS record response and redirect all further queries to your own server. Given the politics involved in DNSSEC, and the current anti-crypto climate, I'd say the chances of a fully-chained DNScurve deployment ever happening are about absolute zero.

No, DNSCurve doesn't authenticate DNS records, it only secures integrity and privacy of your requests (and the responses). DNSCurve and DNSSec don't solve the same problem, they're actually complementary.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.