Earlier quoted context omitted.
> Query ID prediction attacks are not in fact the point of DNSSEC Do you deny DNSSEC's goal is to protect DNS data? Do you deny "Query ID prediction attacks" (or more generally, flooding attacks) aim to corrupt DNS data? Do you deny the 16-bit transaction ID allows for effective flooding attacks? As for "almost nothing in the DNS is signed", while it's true the percentage of second-level domains aren't signed, the DN…
I deny that query ID protection was the impetus for the development of DNSSEC and that the earliest advocacy for it as an operational security tool, rather than a (government-funded) design improvement for the entire TCP/IP stack, was about query ID prediction. Like you, I was there at the time; if the NANOG archives go back that far, you'll see me on the threads babbling about this. This notion of DNSSEC signatures…
In any event, that's a nice site that provides useful stats.