3 ms·
> But it's probably worth remembering that DNSSEC is a PKI over which the USG and its Five Eyes partnership has enormous, outsized influence; they have de facto
by saber6 7y ago
> But it's probably worth remembering that DNSSEC is a PKI over which the USG and its Five Eyes partnership has enormous, outsized influence; they have de facto custody over the most important TLDs on the Internet, a demonstrated willingness to intervene in DNS for policy goals, and, unlike a suborned CA, the TLDs cannot be revoked when the IC abuses them.
You're off base.
DNSSEC is not any more nebulous than the existing structure and control mechanism with regards to domain names. It (mostly) is adding cryptographic under-pinnings to the responses. The control remains the same (registrar level).
- tptacek 7y agoI'm not off base, and the Five Eyes governments obviously control the most important TLDs, as anyone who was around during the piracy seizures knows. The control remains the same, yes: controlled by the USG.