From tptacek's FAQ ( http://sockpuppet.org/stuff/dnssec-qa.html ):
> What’s the alternative to DNSSEC?
> Do nothing. The DNS does not urgently need to be secured. > All effective security on the Internet assumes that DNS lookups are unsafe. If this bothers people from a design perspective, they should consider all the other protocol interactions in TCP/IP that aren’t secure: BGP4 advertisements, IP source addresses, ARP lookups. Clearly there is some point in the TCP/IP stack where we must draw a line and say “security and privacy are built above this layer”. The argument against DNSSEC simply says the line should be drawn somewhere higher than the DNS.