upvote
reply
That rebuttal held water 10 years ago, but fortunately we have made a lot of advancements since then.

DNSSEC was a solution trying to solve the problem of DNS security while still maintaining transparency for DNS operators to spy on queries. At the time, passive DNS was one of the tent poles of tracking malware and responding to security incidents.

We have since committed entirely to transport security in the form of DoH and friends. It solves the vast majority of problems we actually have.

reply
Such as? And do those solve the same thing? The post lists 8 headlines why it should be abolished.
reply
So DNS should be open to MITM attackers?
reply
Even with DNSSEC, it still is. Example: https://blog.cloudflare.com/de-tld-outage-dnssec/
reply
Did you read the article? It's saying that DNSSEC as an implementation to prevent MITM is flawed; other solutions that protect against MITM are proposed.
reply