Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

DNSCurve is used to encrypt queries to authoritative DNS servers. DoH is only used to encrypt DNS queries to third party DNS caches. Using third party caches can open the door to cache poisoning. Cache poisoning can be and has been used as a "justification" for deploying DNSSEC.


Right, but (1) most of the value of secure transport for DNSSEC is in the "last mile" between the resolver and the stub resolver on the laptop or whatever, and (2) the same model that secures that hop can secure authoritative lookups for resolvers --- neither protocol is widely deployed for authority queries for recursors, but DoH already has huge deployment numbers for the other use, and seems the more likely bet for how this will play out going forward.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: