Paul Vixie: Whither DNSCurve? [2010]
isc.org
isc.org
I have a few questions, in case anybody is interested in any of them:
1) Would full deployment of IPsec render DNSCurve unnecessary?
2) Isn't "full security" impossible until DNS queries are encrypted? I'm reading the ongoing comments about HSTS [+] and can't help to think that, if you assume the network is a malicious medium, then any unencrypted DNS query, including DNSSEC, can receive a compromised response. But then again, Paul Vixie's quoted sentence seems to counter my reasoning/understanding.
I voted the submission up, by the way; thanks for posting it. I hadn't read it.