Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

DNSSEC is just replacing one set of roots (the CAs) with another (the root servers).

At least with CAs you can (theoretically) remove trust from a subset of them and things (mostly) keep working.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: