3 ms·
This thing is as old as DEFCON 2011 (see http://blog.thoughtcrime.org/ssl-and-the-future-of-authenticity http://blog.thoughtcrime.org/ssl-and-the-future-of-auth
by itsnotvalid 15y ago
This thing is as old as DEFCON 2011 (see http://blog.thoughtcrime.org/ssl-and-the-future-of-authenticity http://blog.thoughtcrime.org/ssl-and-the-future-of-authentic...) but in view of current events of certificate trustworthiness, there is quite a chance for anything that can successfully replace the approach of trusting CAs.
Please view this blog entry (from the core author of convergence.io) to get the idea of also why DNSSEC is not a good approach (he had put it in the way that it's worse than CAs.)