Edit: Nvm, DNSSEC still has to trust the validating resolver, DNSCrypt solves this.
Edit: Nvm, DNSSEC still has to trust the validating resolver, DNSCrypt solves this.
DNSSec => Authenticity of resource records
DNSCrypt, DNSoverTLS => Privacy of the connectionI still see DNSSec as providing value before the entire graph of DNSCrypt or DNSoverTLS exists.
DNSSEC provides no value at all until graph coverage is reached, and even then provides absolutely no privacy.
DNSCrypt has been designed to both authenticate, authorize and encrypt the channel.
Using both in conjunction means that you have a private connection with authenticated data coming from the upstream resolver. Now the obvious issue is you don't know what the upstream resolver does with that...
https://sockpuppet.org/blog/2015/01/15/against-dnssec/
In the real world, for privacy, there are essentially two competing approaches: DNSCrypt and DNS-Privacy. Both are unrelated to DNSSEC. DNSCrypt uses a custom protocol to encrypt DNS transactions, and DNS-Privacy uses TLS. Neither require, or even benefit from, deployment of DNSSEC.