Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> Another security mechanism in widespread use is HTTPS. This has been available since around 1994, and has gotten a refresh with TLS in 2000. Like SSH many web masters don’t really care how this work, they just know to get certificates from Certificate Authorities, put some lines into their configuration files and it works.

No, it doesn't work[1]. There's only the illusion of CA certification security and nothing more. So if the argument here is that DNSSEC failed because it's not like OpenSSL CA I'm not really buying it - that said I reckon that it's better for software to be easier to configure but as man with white hair and weird look in his eyes said things should be as simple as possible, but not more.

[1] https://www.youtube.com/watch?v=pDmj_xe7EIQ



I never claimed that it worked perfectly. We masters just know what to do and feel secure. More clueful webmaster know to look further.

For DNSSEC most don't even have a clue what to do and Google fu is not going to help and that's what's wrong.


Thank you for that link! That was really an eye opening talk.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: