In lieu of the 8000 word post I wrote about DNSSEC a few months ago, I instead offer this pithy comment: https://news.ycombinator.com/item?id=8564854
@tqbf Is it naive of me to think that any big nation-state adversary can get a forged cert issued as easily as it could alter a DNSSEC zone?
-
@thatcks But: with widespread deployment of HPKP or TACK, to forge a cert, NSA has to risk burning an entire CA. -
@thatcks Meanwhile: there’s no such thing as “burning” a DNS zone. We START OUT knowing they’re compromised. -
@thatcks Comparably difficult tasks.
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.
Thomas Ptacek
Chris Siebenmann