Hacker News new | past | comments | ask | show | jobs | submit login

You forgot the more pragmatic reason: middleboxes. HTTPS works everywhere, and introducing a new(2 years old) protocol (DNS over TLS) working on a new port (853) is a sure way to make sure it does not work in many places.



That mostly applies to corporate environments which already want to use their own resolvers anyway. For most people DNS over dTLS should work fine and if anything should be implemented on the OS level.

Your browser is not special, everything could benefit from secure DNS.


Well, once OS starts doing it maybe mozzilla will switch to that as default...




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: