Hacker News new | ask | show | jobs
by buffrr 1976 days ago
To answer your first question, with the present DNS, If you use DANE, the trust is centralized since you have to trust the root DNS keys and the registrar (imo still better than trusting a large number of CAs. letsencrypt already relies on DNS to issue certificates).