logoalt Hacker News

indoleringyesterday at 7:19 PM1 replyview on HN

True, but DNSSEC doesn't need to worry about forward secrecy and it doesn't need quantum protection until someone can start breaking keys in under a year. Hopefully we will find more efficient PQC by then.


Replies

tptacekyesterday at 7:22 PM

People tried to move DNSSEC from RSA to ECC more than a decade ago. How'd that migration go? If you like, I can give you APNIC's answer.

show 1 reply