|
|
|
|
|
by giovannibajo1
4657 days ago
|
|
The only problem with DANE is that it doesn't protect from NSA. You are simply moving trust from CAs to your TLD owner. Whoever controls your TLD (and whoever can subpoena them) is able to change your zone file without you realizing it. |
|
The point of this is to, hopefully, slowly get people to start actually verifying certificates instead of just randomly assuming that they are secure.