|
|
|
|
|
by matthew9219
1117 days ago
|
|
> Meanwhile if DNSSEC's vision is ever fully realized, you will lose that control entirely. There is no CT there, and even if it was build somehow it will be useless as it has no "teeth" This is a false dichotomy. DNSSEC secures DNS records, it doesn't prevent logging certificate issuance. |
|
That matters because, as the person you were replying to explained, there’s no plausible way to build such a thing. We have CT because the browser developers insisted on it and they control the clients but DNSSEC doesn’t have an equivalent party with that kind of leverage.