|
|
|
|
|
by woodruffw
566 days ago
|
|
The problem with the CA system is arguably not that it’s a single point of failure: it’s that it’s N points of failure, all of which were originally unaccountable to user agents. The CAs are themselves decentralized entities, and each was largely unaccountable to the larger web PKI until CT came along. I think a DNS layer would probably make that problem worse, not better, which is one of the enduring criticisms of DNSSEC and DANE. |
|