Hacker News new | past | comments | ask | show | jobs | submit login

It would still be better than nothing, and would be easier to deploy. DNSCurve would also be good though.

No, it is is substantially worse than nothing, and catastrophically expensive to deploy.

I am talking about the new version the parent proposed, not the current DNSSEC.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact