Florian Weimer fweimer at bfk.de
Fri Jun 19 09:41:16 UTC 2009

* Paul Vixie:

> re:
> http://yro.slashdot.org/story/09/06/16/1657255/A-Black-Day-For-Internet-Freedom-In-Germany

The filtering is supposed to be open and plainly visible anyway, so
DNSSEC doesn't cause any problems.

In an abstract sense, DNSSEC was designed to cut down the number of
possible name resolution results.  Therefore, it is quite compatible
with filtering.

