The security concerns are real. Don't get me wrong, we ought to all give Verisign the smackdown on this. (And by the way, it's possible that this is not even a violation of the contract under which they operate the root servers. Just because nobody imagined the put it in the contract that they can't do it.) But it just occured to me that to the average end user, there's not a lot of difference between the Verisign results and the Microsoft results when you type something in wrong. (I'll leave any comments to the effect that comparing a practice to something Microsoft does is hardly a ringing endorsement as an exercise for the class.)
It will be interesting to see how long the ISC delegation workarounds take to filter around.
|