> Another security mechanism in widespread use is HTTPS. This has been available since around 1994, and has gotten a refresh with TLS in 2000. Like SSH many web masters don’t really care how this work, they just know to get certificates from Certificate Authorities, put some lines into their configuration files and it works.
No, it doesn't work[1]. There's only the illusion of CA certification security and nothing more. So if the argument here is that DNSSEC failed because it's not like OpenSSL CA I'm not really buying it - that said I reckon that it's better for software to be easier to configure but as man with white hair and weird look in his eyes said things should be as simple as possible, but not more.
No, it doesn't work[1]. There's only the illusion of CA certification security and nothing more. So if the argument here is that DNSSEC failed because it's not like OpenSSL CA I'm not really buying it - that said I reckon that it's better for software to be easier to configure but as man with white hair and weird look in his eyes said things should be as simple as possible, but not more.
[1] https://www.youtube.com/watch?v=pDmj_xe7EIQ