Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I think we're talking past each other. There's no uncertainty about how DNSSEC works between servers. Any recursive lookup can validate a signature chain.

The question is how DNSSEC breaks down in the last mile, where recursive lookups aren't happening. A stub resolver --- every resolver on an ordinary workstation is a stub resolver --- can absolutely be tricked by its upstream DNS server. Quad9 can lie to clients about whether it validated DNSSEC, or whether DNSSEC was present at all.

 help



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: