top | item 8906082

Questions and Answers from “Against DNSSEC”

13 points| zedpm | 11 years ago |sockpuppet.org

3 comments

order
[+] tptacek|11 years ago|reply
If this is nearly as interesting or useful than the original post it concerns, I did something wrong.
[+] msturgill|11 years ago|reply
The author of this is missing the point of DNSSEC.

They seem to be confusing DNSSEC and functionality that is possible with DNSSEC (DANE/TLSA). Not only that, they don't seem to fully understand DANE (there are modes that complement the traditional CA model, not replace it).

DNSSEC is just another tool. It isn't a panacea.

I definitely urge readers to objectively research the technical aspects of DNSSEC and draw conclusions for themselves.

[+] owly|11 years ago|reply
Good post. Interesting info.