Hacker News new | past | comments | ask | show | jobs | submit login

The place where DoH is common is the place with no network effect. Anyone can use anything from DoH to DNSCurve to OpenVPN to secure the path between the client and the recursive DNS server, and can do so regardless of what anybody else uses for that.

The thing we're still missing is something to secure the path between the recursive and authoritative nameservers, which is the thing DNSCurve is actually better at and is also not the thing DoH is commonly used for. Moreover, "adoption" is basically code in this context. You could have widespread adoption of DNSCurve just by adding support for it to the handful of open source DNS servers in widespread use.




DNSCurve does make some requirements around the naming of DNS servers, as the name is used to provide the keys. Making:

    uz5xgm1kx1zj8xsh51zp315k0rw7dcsgyxqh2sl7g8tjg25ltcvhyw.nytimes.com.
Be the required the name of your DNS server is a bit offputting. You can always CNAME it though for better ergonomics.

(example is from: https://dnscurve.org/out-install.html)


This is basically irrelevant, normal people don't interact with the names of authoritative DNS servers.


Operations people frequently pick based on ergonomics. The bad ergonomics and having to learn new tools is a frequently cited reason why IPv6 is seeing lesser adoption.




Join us for AI Startup School this June 16-17 in San Francisco!

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: