|
|
|
|
|
by sarciszewski
3875 days ago
|
|
Okay, so this is what happens: 1. Evil NSA compromises CA in BFE 2. Evil NSA subverts DNSSEC for COM to publish a bad CA certificate 3. Some combination of Google Certificate Transparency + HPKP discovers this, the CA in BFE gets removed from browsers If your point is "DNSSEC is pointless", OK. But it sounds like you're saying it makes us less secure. I'm just trying to figure out how that could even be. |
|
What I (and you) seem to have assumed was that this was DNS based certificate pinning, which to me would have made a lot of sense.