|
|
|
|
|
by devrand
1030 days ago
|
|
That's not really any better than what we have now. In your model you need to have full trust in the DNS operator and that your DNS responses weren't MITM'd (which are still generally unencrypted!!). In other words, you're just trading trusted CAs for trusted DNS operators. |
|