> Yes, except that DNS-over-TCP helps reduce the risk of MITM, which > is a perceived channel-validation benefit of DNSSEC.
How does DNS/TCP reduce MITM risks enough to talk about? How is DNS/TCP a problem for governments and other bad actors? 25 years ago I naively assumed that "transparent" and "translucent" proxies for popular TCP based protocols were not practical at scale. Then AOL started proxying port 25 and now everyone has man in the middle proxies for all kinds of TCP applications including some that are ostensibly protected with TLS. Vernon Schryver [email protected] _______________________________________________ dns-operations mailing list [email protected] https://lists.dns-oarc.net/mailman/listinfo/dns-operations dns-jobs mailing list https://lists.dns-oarc.net/mailman/listinfo/dns-jobs
