> No. DNSSEC does not encrypt the DNS. After DNSSEC is implemented, everyone will still be able to read DNS. The major difference will be that sites will store their TLS keys in the DNS, and will thus have vouchsafed them with a new set of CAs controlled by the Five Eyes governments.
Fair enough, my knowledge of DNSSEC is limited. I thought it provided confidentiality in addition to authentication, but I see I was mistaken.
I'm still not sure how you arrive at the conclusion that it is a net loss. Which attacks will DNSSEC enable that are not possible today? If you mean that it will give people a false sense of security, is that not the same as TLS today? Despite my hangups with the CA system I think we're better off with TLS than without it.
The NSA certainly has no problems with intercepting DNS requests today with their QUANTUM tools.
I am genuinely interested in hearing other ideas about how to provide confidentiality and authentication for DNS without central trust. Since you have clearly investigated these matters, I would like to ask again, are you aware of any promising projects or ideas in this regard? Because I would jump into the anti-DNSSEC camp in a heartbeat if one existed.