Earlier quoted context omitted.
> 1. DNSSEC doesn't protect against ISPs hijacking DNS responses DNSSEC protects signed zones by allowing clients to notice a suspicious lack of a valid signature on responses that should have been signed. DNSSEC doesn't protect unsigned zones, but that shouldn't surprise anyone and isn't really an indictment of DNSSEC's capabilities. > I'm not sure what difference it makes to be sending packets to the wrong IP. That…
But the clients' stub resolvers don't validate the answers, so how can they notice the lack of a valid signature?
I really don't understand why the existence of software that doesn't try to take advantage of DNSSEC is being used as evidence that DNSSEC is incapable of doing something.