top | item 47209342

(no title)

jcalvinowens | 9 hours ago

It's not a full recursive lookup: you don't understand how DNSSEC works. I'm not replying to you any more.

discuss

order

tptacek|9 hours ago

I'm guessing I do. Anyways: no question that there are a variety of experimental setups in which you can address the problem of on-path attackers trivially disabling DNSSEC, freeing you up to work on the next, harder set of DNSSEC security and operational problems.