Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Calling this "insecure" is a bit harsh. This is required for offline signing which provides better security but worse privacy.


Sorry, you're right. I mistakenly thought this issue was solved by a later standard.


Could that later standard be NSEC3? It’s like the easily walkable NSEC, but with hashed names and special flags for opting out of delegation security features. The 3 appears to stand for the number of people that fully understand how it works…




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: