a: Such resolvers are likely to not ask for DNSSEC at all.
b: Even if they do, they will take a timeout and retry by TCP, which slows things down (by a couple of seconds), but otherwise the results still work. And for the root, queries hit the root so rarely that you're likely to never notice this timeout anyway.