|
|
|
|
|
by Avamander
1301 days ago
|
|
> But that's on top of the domain registry which underpins everything. Everything but trust. A registry lying to issue certificates for its domains will become visible real quick. If CT makes "creaky WebPKI usable" then DNSSEC is just unusable. > Yet most of the large TLDs manage with less screwups than many of the CAs. Hard to screw up what you don't have. Even if a bunch do implement DNSSEC, nobody has really trusted them with the task in a way that it'd actually matter. TLD operators can't even mandate the use of DNSSEC by registrars, requiring audits is lightyears away in comparison. WebPKI at least does that. Nobody in their right mind would be claiming an opaque system with zero oversight is somehow better for trust, than the alternative. |
|
I don't know what you base your experience on, but it is not representative of the better ccTLDs. The oversight there are beyond what you have in any CA. That much is a fact.
If you have specific criticism, feel free to ask any of the people concerned at for example the next IETF. In my experience criticism is welcomed and listened to. That is, indeed, what builds trust.