|
|
|
|
|
by dane-pgp
1176 days ago
|
|
Trusting the country that operates the ccTLD of your website is a much better situation than having to trust all the countries that have CAs operate in them. A malicious CA in one country can issue a fraudulent certificate for a site in another country, whereas the people operating .ru can't affect the records for example.us so the blast radius is limited by design. Moreover, no one is required to use a ccTLD, and there are hundreds of gTLDs to choose from, or you could even run one yourself if necessary. |
|
Sure and they'll be quickly mistrusted. You can't really revoke DNNSEC trust of an ccTLD operator.
> Moreover, no one is required to use a ccTLD, and there are hundreds of gTLDs to choose from, or you could even run one yourself if necessary.
This is bypassing a dangerous design, at best.