If an ISP ��(or anyone) is breaking/changing TTL's (and
maybe other stuff in DNS) on purpose I would think IMHO this is
bad. Think would make DNSSEC signed zones fail + other stuff you
have said as the ISP is playing around with it.
Um, no, messing with the TTL doesn't break DNSSEC (the TTL isn't
signed), although potentially a vastly extended TTL could push
caching of a DNSSEC records beyond the expiry of their keys. (If a
< 24 hour expiry did this, whoever is maintaining the DNSSEC
keys is Doing It Wrong.) But in general, every recursive name
server updates the TTL of its cached records every time it issues
a cached answer to a query.