Comment by account42
2 hours ago
Web PKI also has not had transparency logs until fairly recently. And Web PKI revocation is a joke as well. At least a "rogue" DNSSEC signer can only sign domains they have been delegated authority over and not literally everything.
No comments yet
Contribute on Hacker News ↗