Comment on Security for the peopleComments−Tepix11yNitpicking:They should use a SHA256 certificate :-)And DANE and TLSA−tptacek11yBaffling that anyone could still be advocating for DANE after the NSA slides indicating that the USG has owned up CAs came out. Why exactly does anyone believe the DNS roots are harder to own up?
Comments
Nitpicking:
They should use a SHA256 certificate :-)
And DANE and TLSA
Baffling that anyone could still be advocating for DANE after the NSA slides indicating that the USG has owned up CAs came out. Why exactly does anyone believe the DNS roots are harder to own up?