Hacker News new | ask | show | jobs
by takeda 3876 days ago
You can make your DNS server ignore root certificate and use anchors stored locally for specific TLD.

If then you contact a TLD that's owned by 3rd party you essentially trusting whoever owns that TLD. For example .google is owned by Google, so whatever is under it is under their full control.

1 comments

"DNSSEC is fine, as long as we all give up on .COM". Ok.