| ▲ | megous 2 days ago | ||||||||||||||||
they can fetch the key or its hash from DNS. it's not like the current system is that much more involved. current system is basically a third party signed cache of such ownership claims validated based on ability of someone to modify DNS records. All caches are just functionally useless layers..., so that's that. | |||||||||||||||||
| ▲ | coldpie 2 days ago | parent | next [-] | ||||||||||||||||
How do I know that the DNS record is owned by the entity they are claiming to be? CAs have nothing to do with caching. | |||||||||||||||||
| |||||||||||||||||
| ▲ | mirashii 2 days ago | parent | prev [-] | ||||||||||||||||
DNS can be trivially MITM'd as well, it's certainly not a secure mechanism for distributing keys. | |||||||||||||||||
| |||||||||||||||||