logoalt Hacker News

tptacekyesterday at 7:22 PM1 replyview on HN

People tried to move DNSSEC from RSA to ECC more than a decade ago. How'd that migration go? If you like, I can give you APNIC's answer.


Replies

indoleringyesterday at 7:29 PM

RSA is still fine given that you can't break it in a year and we aren't worried about forward secrecy.

Also, I worked for a DNS company. People stopped caring about ulta-low latency first connect times back in the 90s.

You are clearly very proud of your work devaluing DNSSEC. But pointing to lack of adoption doesn't make your arguments valid.

show 2 replies