Skip to content

Comment on STARTTLS Considered Harmfulparent

Comments

One reason DNSSEC is unpopular is that it fails to address the fact that centralized PKI suffers from tons of problems. Those problems would defeat the purpose of a gesture as serious as putting your gpg key in DNS.

It always seems ridiculous to me that people are coming up with ways to cope with universal CAs (Tack, Convergence, CRLSets, etc.), but can't imagine how to apply those same ideas with a hierarchical system.

CAs are a problem that DNSSEC doesn't solve, but DNSSEC solves tons of other problems without making the CA problem harder.

I think it's unpopular, because it is complex and it doesn't address privacy (between you and your ISP at least).

Centralized, hierarchical PKI is ok here, because it is better than what we have now (600 CAs for TLS, unsigned DNS, etc.) and nobody has a proposal for a fully decentralized system that ordinary people can understand (as demonstrated by GPG).

Sure but those are the same problems that a centralized domain name system suffers from. Currently, we have the privilege of paying for a second centralized system (CAs) which solves none of them.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.