Skip to content

Comment on 'Trivially easy' to buy SSL certificate for domain you don't ownparent

Comments

Hacker News really sucks for quoted point-by-point responses. I don't think that's an accident. Try writing standalone comments.

After more than 13 years of failed attempts to secure the DNS, you need to better than "we haven't actually tried it yet". DNSSEC enthusiasts could have made the same argument 8-9 years ago with the "original" DNSSEC protocol, which ended up being scrapped.

Meanwhile, the operational problems DNSSEC will cause are, I think, entirely relevant to DNSSEC's role in web security --- both because of the weaknesses in DNSSEC that would directly impact its utility as a CA (for instance, the role of stub resolvers), and because of the damage it could inflict on the rest of the stack.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.