|
|
|
|
|
by wav-part
2718 days ago
|
|
> No. You have to trust all the CAs, and the governments that control the DNS. Not in DNSSEC. .xxx need only trust dnsroot. yyy.xxx need only trust .yyy and dnsroot. firefox/chrome/etc with support from important orgs with high value names (google.com/bankofamerica.com/etc) would then make sure that dnsroot/.com/etc do not abuse the trust. They have incentive and methods of punishment. There is no legal authority that clients need to map DNS . to existing root keys. A client can map a.b.c to any key it wants. The risk of gov overreach is same for both tls and DNSSEC. DNSSEC just trusts fewer entities. The only people who benefit from current system, are CAs who are getting $$$ for nothing. > https://www.imperialviolet.org/2015/01/17/notdane.html This is orthogonal. Weak Keys are not required or implied characterstic of DNSSEC. |
|