DNSSEC is not about encryption, it's about crypto signing of records.If the DNS record is changed encryption is not going to help.
I sticking with QUAD9 for now.
Sent from my P027 using Tapatalk
DNSSEC is not about encryption, it's about crypto signing of records.If the DNS record is changed encryption is not going to help.
I sticking with QUAD9 for now.
DNSSEC is not about encryption, it's about crypto signing of records.
Sent from my P027 using Tapatalk
They can also steal valid encryption certificates for an organization's domain names.
I for one have learnt something new today.The signing keys are stored on root servers, not on your computer or your upstream server.
I don't think you understand how DNSSEC works - I recommend reading up on it. Again, you are mixing up technologies like DoT/DoH, and DNSSEC. The signing keys are stored on root servers, not on your computer or your upstream server. The chances of these servers getting compromised are slim to none.
How many root servers are there around the world?
I don't remember however if the keys are on the actual root servers, or on the TLD root servers.
Keys are part of the domain record - for "example.org", the keys are there...
We use essential cookies to make this site work, and optional cookies to enhance your experience.