logoalt Hacker News

dns_snektoday at 3:47 PM1 replyview on HN

Because that only protects you from a small subset of possible threats that end-to-end encryption protects you from like DNS hijacking and any MITM-type scenario.

Sticking it on a VLAN only controls access, not data secrecy.


Replies

VladVladikofftoday at 4:52 PM

Broadcasting internal IPs on public DNS records is also a suboptimal approach that leaks information to the public. Local devices should be routed over layer 2.

show 1 reply