https://tonyarcieri.com/on-the-dangers-of-a-blockchain-monoc...
https://paragonie.com/blog/2017/07/chronicle-will-make-you-q...
> Not if zone operators upgrade to ECDSA as defined for DNSSEC in https://tools.ietf.org/html/rfc6605
First: That's a big "if". Lots of RSA legacy support.
Furthermore, ECDSA is so bad that Ed25519 and Ed448 are even coming to FIPS 186-5 later this year.
Citing ECDSA adoption in DNSSEC doesn't make as strong of a case as you might think.