4 ms·
Which leads us back to needing caching, which needs a signatory, and a list of trusted signatory, which gets us back to certificate authorities. Gotcha :-).
by quickthrower2 3y ago
Which leads us back to needing caching, which needs a signatory, and a list of trusted signatory, which gets us back to certificate authorities. Gotcha :-).
- stephenr 3y agoCaching is something DNS already has in-hand.
- quickthrower2 3y agoUsing a distributed MITM system! https://www.cloudflare.com/en-au/learning/dns/dns-cache-poisoning/ https://www.cloudflare.com/en-au/learning/dns/dns-cache-pois...
- stephenr 3y agoPerhaps you're unaware, but that problem can be largely mitigated by DNSSEC, which is why it's considered a requirement to make DANE practical.