logoalt Hacker News

megoustoday at 7:11 PM2 repliesview on HN

they can fetch the key or its hash from DNS. it's not like the current system is that much more involved. current system is basically a third party signed cache of such ownership claims validated based on ability of someone to modify DNS records.

All caches are just functionally useless layers..., so that's that.


Replies

coldpietoday at 7:20 PM

How do I know that the DNS record is owned by the entity they are claiming to be? CAs have nothing to do with caching.

show 1 reply
mirashiitoday at 7:20 PM

DNS can be trivially MITM'd as well, it's certainly not a secure mechanism for distributing keys.

show 1 reply