Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

No, we wouldn't, you're right. We'd just replace LetsEncrypt and the ISRG with the security track records and policy integrity of the major DNS providers, many of which are state-controlled, and the largest of which are too important to revoke.

Really hard to understand why that hasn't happened yet!

 help



You can chose under which registry you can register your domain. You cannot choose which (in many cases also state controlled) web PKI certificate authority can sign certificates for your domain name. And Web PKI revocation is a joke that many clients don't check at all and others do using privacy-hostile mechanisms.

But sure, keep spreading FUD like you always do on this topic.


For the last 2 years, I've tracked the Tranco Top 1000 sites, continuously checking DNS to see if any major sites have turned on DNSSEC (6% of the Top 100 do --- many of them government sites). Over those last 2 years, a total of 8 sites in the Tranco list have enabled it. It happens so rarely I could reasonably call them on the phone and share my misinformation about how moribund DNSSEC is to them directly.

https://dnssecmenot.fly.dev/

The PKI run by state-level actors isn't going to happen.


> You cannot choose which (in many cases also state controlled) web PKI certificate authority can sign certificates for your domain name.

Are there any remaining CAs in browser root stores that don’t enforce CAA record validation?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: