It’s more likely they are confused because of all of the conflicting opinions on the web. You’ll see people on HN who seem to have a personal vendetta against DNSSEC for reasons that only make sense to them.
For example, a common argument is that DNSSEC is controlled by world governments, as if certificate authorities and domain registries are free-standing entities separate from the countries they’re based in.
Many of these folks are actually misinformed, but there are quite a few who are clearly disingenuous about how DNSSEC works.
Let's clear this up: DNSSEC creates a chain of trust, from the root zone (the “.” at the top of the domain hierarchy) to your zone, such as example.com.
The chain is
. --> com --> example.com
Browsers trust hundreds of root and intermediate certificate authorities that can issue a certificate for any domain. This has happened more than a few times.
The DNSSEC trust chain is far more constrained and you get to create the KSK and zone signing keys (ZSK) for your zone.
Root Key Signing Key (KSK) is the public key of the key pair that’s for the root zone. The private key of this key pair is used to sign the top-level domains such as .com, .net, .org, etc.
The root KSK ships with all of the DNSSEC-supporting DNS resolvers and enables them to verify the authenticity of the trust chain.
It’s not clear what the paranoia is about; the public KSK is public; it’s referenced on thousands of websites and everyone involved with running the global internet knows about it. [1]
If something malicious or nefarious were to happen, all registries, regional internet operators, ISPs, etc. would immediately know about it.
All of the DNS resolvers that support DNSSEC have a built-in way to automatically upgrade to a new KSK when it’s released [2]. Even if you imagine the world’s governments colluding to change the key for whatever nefarious reason, DNS resolvers know not to trust any new key unless it’s been available for 30 days.
(The new key would need to be signed by the old key anyway, but for the sake of arguement, lets pretend that’s not neccessary.)
What those people neglect to mention is you’re not required to trust the root KSK. You can decide where your chain of trust starts if you wish, including only trusting your own zone. You can also create islands of trust, zones or domains you feel comfortable with.
Anyway, you can read rational, fact-based responses to these and other DNSSEC falsehoods. [3]
[1]: https://www.iana.org/domains/root
[2]: https://tools.ietf.org/html/rfc5011
[3]: https://easydns.com/blog/2015/08/06/for-dnssec/