Hacker News new | ask | show | jobs
by j16sdiz 566 days ago
> wouldn’t a potential solution be to layer independent verification mechanisms on top of the current system?

CT[1] allows some kind of external audit, but this is _mostly_ after the fact.

DNSSEC have much worse trust issue.

[1] https://certificate.transparency.dev/howctworks/