zlacker

[return to "I read the federal government’s Zero-Trust Memo so you don’t have to"]
1. scarmi+Nf1[view] [source] 2022-01-27 20:37:31
>>EthanH+(OP)
This sounds really beautiful, and I am saving the link for future reference.

I'm curious about the DNS encryption recommendation. My impression was that DNSSEC was kind of frowned upon as doing nothing that provides real security, at least according to the folks I try to pay attention to. Are these due to differing perspectives in conflict, or am I missing something?

◧◩
2. zie+oS1[view] [source] 2022-01-27 23:35:44
>>scarmi+Nf1
DNSSEC is security in the other direction( DNS server -> client ). All DNSSEC does is securely sign all the responses to DNS queries.

so DNSSEC is the answer to, can I trust this IP is valid for the name news.ycombinator.com.

DNS over TLS/HTTPS just says, nobody but the DNS server I use can see I'm wanting news.ycombinator.com's IP. It's mostly useless at the moment, since other gaps exist leaking essentially the same information(SNI, etc), but it should get more useful over time, as people are working on fixing those gaps.

[go to top]