Hacker News new | ask | show | jobs
by bawolff 479 days ago
Nothing saying you can't, just when people talk about DANE that is usually not what they are proposing.

In terms of what you are saying, i think the main objection would be that HPKP feels a lot easier then putting it in DNS and we couldnt even get that to work. Otoh maybe dns could do a lot lower ttl which would counter some of the risks.