▲ | ryao 4 days ago | ||||||||||||||||
How about TLS without CAs? See DANE. If only web browsers would support it. | |||||||||||||||||
▲ | pornel 3 days ago | parent [-] | ||||||||||||||||
DANE is a TLS with too-big-to-fail CAs that are tied to the top-level domains they own, and can't be replaced. Separation between CAs and domains allows browsers to get rid of incompetent and malicious CAs with minimal user impact. | |||||||||||||||||
|