There's no reason to think that running your own copy of DNSSEC + Unbound would have helped here. Firstly, Google don't have DNSSEC signed DNS data, which renders the feature moot. But even if google did, DNSSEC would have triggered the same kind of error that TLS did; the knowledge of a false answer. It wouldn't have resulted in a correct answer.
DNSCurve is more robust in that respect. It's very hard to tamper with the data stream other than to break it entirely.
Yes but DNSCurve is hop-to-hop and solves a different problem. If you are able to take a over a resolver between the victim and the TLD, you can easily hijack DNSCurve.
DNSCurve is more robust in that respect. It's very hard to tamper with the data stream other than to break it entirely.