
23 Oct
2017
23 Oct
'17
1:37 a.m.
On Mon, 23 Oct 2017 14:02:45 +1300, Simon Green wrote:
To me, enabling DNSSEC is more important than DNS over TLS. DNSSEC ensures that a caching nameserver can verify that the DNS request has not been tampered with during transit.
Which is hardly a big issue, when you have end-to-end encryption (SSH, SSL/TLS). And also quite different from the issue being addressed here.