DNS needs to be connectionless; it’s building block protocol for TCP. DnsCurve is much closer to what we actually need.
DNS needs to be connectionless; it’s building block protocol for TCP. DnsCurve is much closer to what we actually need.
I've also written about performance of DNS over TLS [3] and found it to be negligible. The TLS setup is only done infrequently.
[1] https://ianix.com/pub/dnssec-outages.html [2] https://cyounkins.medium.com/costs-and-benefits-of-local-dns... [3] https://cyounkins.medium.com/performance-of-dns-over-tls-4f4...
TLS DNS provides confidentiality, in addition to hop-by-hop integrity; DNSSEC provides no integrity, which has led to a decade of rationalizing by its advocates about DNS not "needing" confidentiality.
This doesn't make any sense as you could use DNS and TCP separately (for example finding a hostname using DNS to connect your video streaming ingestion server running via UDP and hardcoded addresses to bootstrap installation files via TCP respectively).
(musl doesn't even try DNS/TCP after receiving a TC packet)