FINDING · POLICY

DNSSEC fails to withstand legal attacks because governments can legally compel DNS authority operators to manipulate entries and certify the changes; the trust chains DNSSEC establishes mirror DNS zone delegations and therefore inherit the same jurisdictional vulnerabilities. A Danish police incident demonstrated the collateral damage: 8,000 legitimate domains were accidentally removed when censorship procedures were executed against a single target. Chinese DNS injection has been shown to have worldwide effects on name resolution through out-of-bailiwick NS record chains.

From 2014-wachs-censorship-resistantA Censorship-Resistant, Privacy-Enhancing and Fully Decentralized Name System · §1, §2.2 · 2014 · Cryptology and Network Security

Implications

Tags

censors
cngeneric
techniques
dns-poisoning

Extracted by claude-sonnet-4-6 — review before relying.