Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It's in fact very difficult to imagine mandatory transparency logs in the DNS PKI. The story of how mandatory logs came to be for TLS involved Google and Mozilla putting a gun to the heads of the CA industry, after murdering several of them. Nobody can do that to the DNS, and just as importantly, governments don't want them to.


In a world where DANE catches on on the web, I don't see why Google and Mozilla couldn't do that again. I mean, presumably there'd need to be some evidence of malfeasance, like there was with Web PKI. I don't see why Mozilla alone couldn't start by putting the screws to a smaller CCTLD and some medium-sized DNS hosts for instance.

That said, I don't particularly see DANE growing on the web.


Google and Mozilla can't "dis-trust" .COM. They're stuck with it.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: