Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Why can't I add my site's certificate as a DNS record, use DNSSEC and be done?

I don't want to give Symantec (owner of Verisign) money or trust to do something I can easily do myself.



because DNSSEC isn't required.

As an example, if i mitm your dhcp request, i insert myself in as your dns server and gateway and i just say that DNSSEC isn't enabled for this domain. You have to trust me, and I can give you a MITM'd page.

Similarly dnssec uses a very similar model. You need somebody to sign that your record is valid which is roughly the same as somebody signing your certificate as valid. They are both a chain of trust, they just differ slightly in implementation.

I do agree with you that using dnssec makes more sense then our current system.


That's what djb's CurveCP is trying to do (http://curvecp.org/) (except with DNSCurve and custom protocols)




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: