logoalt Hacker News

indoleringtoday at 5:39 PM1 replyview on HN

> DNSSEC is moribund.

You’ve clearly put a lot of effort into limiting adoption. I’d really value your thoughts on this response to your anti-DNSSEC arguments:

https://easydns.com/blog/2015/08/06/for-dnssec/


Replies

tptacektoday at 5:43 PM

I'm sure you can find several of those using the search bar. The argument has gotten a lot grimmer since 2015 --- DNSSEC lost deployment in North America over the last couple years. It didn't simply plateau off and stop growing: people have started turning it off. That corresponds with the success of CT in the WebPKI, with multi-perspective lookup, with the failure of DANE stapling in tls-wg, and with domain hijacking through registrar fixing.

show 1 reply