| ▲ | moquilabs 2 hours ago | ||||||||||||||||
In the FAQ of this article it says: > What’s the alternative to DNSSEC? > Do nothing. The DNS does not urgently need to be secured. > All effective security on the Internet assumes that DNS lookups are unsafe. This is not true, our entire infrastructure of ACME certificate authorities like let's encrypt are fundamentally dependent on DNS: https://letsencrypt.org/how-it-works/#domain-validation Then TLS verifies the domain with the private key the certificate authority issues... How can you trust the s (secure) in https then?? Can anyone provide an example of "effective security on the Internet"? | |||||||||||||||||
| ▲ | tptacek 2 hours ago | parent [-] | ||||||||||||||||
Virtually none of the most important sites on the Internet are signed. When's the last time one was maliciously misissued? | |||||||||||||||||
| |||||||||||||||||