> Yes, except that DNS-over-TCP helps reduce the risk of MITM, which
> is a perceived channel-validation benefit of DNSSEC.

How does DNS/TCP reduce MITM risks enough to talk about?  How is
DNS/TCP a problem for governments and other bad actors?  25 years
ago I naively assumed that "transparent" and "translucent" proxies
for popular TCP based protocols were not practical at scale.  Then
AOL started proxying port 25 and now everyone has man in the middle
proxies for all kinds of TCP applications including some that are
ostensibly protected with TLS.


Vernon Schryver    [email protected]
_______________________________________________
dns-operations mailing list
[email protected]
https://lists.dns-oarc.net/mailman/listinfo/dns-operations
dns-jobs mailing list
https://lists.dns-oarc.net/mailman/listinfo/dns-jobs

Reply via email to