Comment on CA:WoSign IssuesComments−themihai10yHopefully one day we will replace CAs with something decentralized(i.e based on DNSSEC). CAs make sense only if you need an EV certificate.−Panino10yDNSSEC is not decentralized -- it follows a strict hierarchy from ICANN => TLDs (world governments) => you.DNS is distributed, not decentralized.−themihai10yRight... but at least you cut off the CA from the scheme. You depend on ICANN -> TLD anyway.
Comments
Hopefully one day we will replace CAs with something decentralized(i.e based on DNSSEC). CAs make sense only if you need an EV certificate.
DNSSEC is not decentralized -- it follows a strict hierarchy from ICANN => TLDs (world governments) => you.
DNS is distributed, not decentralized.
Right... but at least you cut off the CA from the scheme. You depend on ICANN -> TLD anyway.