|
|
|
|
|
by aianus
3875 days ago
|
|
Still sounds like an improvement over the current PKI where any CA can sign any cert for any domain. How many roots do you have in your browser's trust store? How many of them would roll over and mis-issue certs if presented with a secret warrant in their country of residence? (All of them.) |
|
https://www.imperialviolet.org/2015/01/17/notdane.html
There are 3873497 CAs your browser has to trust today. DANE adds a 3873498th and a 3873499th, and the ones it adds are controlled by NSA.
The solution to the CA problem is to drastically reduce the power CAs have, which is what is happening with key pinning and certificate transparency and whatever follows that.
The solution to the CA problem can't possibly be "create a new super-CA controlled by governments".