Hacker News new | ask | show | jobs
by briffle 4608 days ago
Placing your public key in a dnssec validated DNS record would be a good way to replace the validation component done by most CA's.
1 comments

If enrolling your key in a PKI controlled by world governments seems like a good replacement for a bad private PKI, yes, by all means, pursue DNSSEC as an alternative.