Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

You can chose under which registry you can register your domain. You cannot choose which (in many cases also state controlled) web PKI certificate authority can sign certificates for your domain name. And Web PKI revocation is a joke that many clients don't check at all and others do using privacy-hostile mechanisms.

But sure, keep spreading FUD like you always do on this topic.

 help



For the last 2 years, I've tracked the Tranco Top 1000 sites, continuously checking DNS to see if any major sites have turned on DNSSEC (6% of the Top 100 do --- many of them government sites). Over those last 2 years, a total of 8 sites in the Tranco list have enabled it. It happens so rarely I could reasonably call them on the phone and share my misinformation about how moribund DNSSEC is to them directly.

https://dnssecmenot.fly.dev/

The PKI run by state-level actors isn't going to happen.


> You cannot choose which (in many cases also state controlled) web PKI certificate authority can sign certificates for your domain name.

Are there any remaining CAs in browser root stores that don’t enforce CAA record validation?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: