|
|
|
|
|
by tptacek
3875 days ago
|
|
I know a lot of people seem to think that, but that's just not right. You can pin a certificate with X.509 CA TLS, and you can theoretically pin a certificate against DNSSEC/DANE (no browser does and it's unlikely they ever will; browsers flirted with DNSSEC a few years ago and that code has been withdrawn). But when you pin an X.509 CA cert, you can also punish CAs that issue fraudulent CAs that break pins. This has already happened several times. When you break a DNSSEC/DANE pin, you have no recourse. Everyone relies on the same .COM keys. |
|