Thanks, that was a good read, and cleared up a lot of misunderstanding I had about DNSSEC!
You make a strong argument that DNSSEC cannot deliver any real advantages. I did not see anything to support your earlier statement that it's worse than nothing, but given the general uselessness of the protocol, I certainly won't be deploying it.