Hacker News new | ask | show | jobs
by leonidasrup 10 days ago
Who should decide that the assignment domain name -> public key is valid?

Certificate authorities?

Domain registrars?

Both of them are subject to government control and regulation and as such Web PKI provides normal commercial level of security, it doesn't protect from government agencies.

To protect from government agencies we would need to move from addressing web pages using domain names to addressing web pages using public keys. This is hard because of Zooko's triangle.

https://en.wikipedia.org/wiki/Zookos_triangle