Earlier quoted context omitted.
I am curious about "but not remain so." You don't think that increased adoption of DNSSEC will make dns spoofing less practical for zones that are signed (assuming properly configured local resolvers eg unbound on 127.0.0.1:53)? Side note:† In the past I recall you supporting developers "pinning" certificates by rolling their own CAs and bundling the keys with their applications. I have always thought that DANE/TLSA…
I meant that DNS spoofing vulnerabilities that are currently impractical against unencrypted DNS might not always be impractical against unencrypted DNS. In the recent discussions about NSA surveillance, a technological anchor we could repeatedly point to was the fact that Google baked the identities of their keys directly into the binaries for Google Chrome. Firefox has adopted the same approach. I don't think it's…
Duh, thank you. I don't know why I was approaching it as if the clients had the DNSSEC keys hardcoded for each zone. It seems that there is not a lot of hope for a solution that is easily interoperable (BYO Browser/MTA) when your threat model includes nation state and sub-nation state threats.