Does this (from Introducing DNSCrypt) clarify anything?

Quote:
Many will remember the Kaminsky Vulnerability, which impacted nearly every DNS implementation in the world (though not OpenDNS).

That said, the class of problems that the Kaminsky Vulnerability related to were a result of some of the underlying foundations of the DNS protocol that are inherently weak -- particularly in the "last mile." The "last mile" is the portion of your Internet connection between your computer and your ISP. DNSCrypt is our way of securing the "last mile" of DNS traffic and resolving (no pun intended) an entire class of serious security concerns with the DNS protocol.

You left me hanging on one point, though: I've been using Open DNS's servers, 208.67.222.222 / 208.67.220.220, and DNSCrypt now shows "Current resolvers: 208.67.220.220 using DNSCrypt."

What's the difference between the two sets of numbers(, and why does the first set drop out when I use DNSCrypt)?

Thanks, again.


The new Great Equalizer is the SEND button.

In Memory of Harv: Those who can make you believe absurdities can make you commit atrocities. ~Voltaire