|
|
|
|
|
by tptacek
3875 days ago
|
|
No. See: https://www.imperialviolet.org/2015/01/17/notdane.html There are 3873497 CAs your browser has to trust today. DANE adds a 3873498th and a 3873499th, and the ones it adds are controlled by NSA. The solution to the CA problem is to drastically reduce the power CAs have, which is what is happening with key pinning and certificate transparency and whatever follows that. The solution to the CA problem can't possibly be "create a new super-CA controlled by governments". |
|
I agree that CAs + DANE is just as shitty or shitter than CAs.
But:
a) In the event DANE replaced the CA system, one super-CA controlled by the NSA is better than 300 CAs essentially controlled by 50 different governments including the NSA.
b) Nobody's making you use DANE. Signed DNS records are an improvement over the status quo regardless of what you think of tying TLS to it.