Why “DNSSEC” is being discussed
The most recent Hacker News stories and comments contributing to this topic's mentions.
Did you read the article? It's saying that DNSSEC as an implementation to prevent MITM is flawed; other solutions that protect against MITM are proposed.
by digitalPhonix · Sep 5, 2026
At a high level, one of 3 things happens: 1. The forwarder gets a response claiming the record is supposed to be DNNSEC signed from the parent (recursively traversing from the r…
by zamadatix · Sep 5, 2026
Sure: zonemaster[1] is the tool we use [2]. It checks for keylengths and other things and allows policies to be defined on them. It comes with a fairly well defined / moder…
by Stitch4223 · Sep 5, 2026
DNSSEC and DoH provide different security services. But to get the benefit of DNSSEC, you need to resolve recursively. DoH works for stub resolvers. That's all I'm saying.
by tptacek · Sep 5, 2026
> To protect yourself from an upstream resolver using DNSSEC, you need to be doing something akin to a full recursive lookup yourself. This is a flaw in the DNSSEC design and a…
by QDwQ1 · Sep 5, 2026
Wait, I must be misunderstanding you, because if you're resolving off Quad9, they can definitely poison your DNSSEC-signed records. Between a stub resolver and a recursor DNSSEC…
by tptacek · Sep 5, 2026
Interest
Proportion of Hacker News items mentioning "dnssec" over time.
Mentions
Total number of Hacker News items mentioning "dnssec" over time.
The Domain Name System Security Extensions (DNSSEC) is a suite of extension specifications by the Internet Engineering Task Force (IETF) for securing data exchanged in the Domain Name System (DNS) in Internet Protocol (IP) networks. The protocol provides cryptographic authentication of data, authenticated denial of existence, and data integrity, but not availability or confidentiality. As of 2026, DNSSEC deployment is spotty. Read more on Wikipedia