I think the post is great, just that its not really clear what users need to do going forward (unsurprisingly; that should really be on nginx). In particular:
> Even pointing to a resolver on your internal local network may be a bad idea. Running a resolver on localhost is the only safe option.
In many cases, going to a localhost-only DNS is going to be way more complicated than getting off e.g. Google's open DNS, and thus conflating them likely means way more people giving up and sitting on untrusted DNS.
> Even pointing to a resolver on your internal local network may be a bad idea. Running a resolver on localhost is the only safe option.
In many cases, going to a localhost-only DNS is going to be way more complicated than getting off e.g. Google's open DNS, and thus conflating them likely means way more people giving up and sitting on untrusted DNS.