Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Cloudflare sells DNSSEC services. They've supported DNSSEC for years, and adoption of DNSSEC in the US --- outside of people who get it by default with Cloudflare --- hasn't budged.

DoH breaks ISP DNS interception immediately, and for all zones, not just the rare DNSSEC-signed ones, by moving DNS resolution off-net to a more trusted provider.

The irony is, breaking NXDOMAIN interception is in fact a core use case of DNSSEC, and the protocol simply won't work for it, because the ocean needs to boil before every vector of the attack is closed. DoH went from the whiteboard to deployment in a tiny fraction of the time, and actually closes this hole decisively.



Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: