Re: [DNSOP] DNS vulnerabilities
Evan Hunt <[email protected]> Fri, 1 Nov 2013 06:35:52 +0000
| Newsgroups | gmane.ietf.dnsext |
|---|---|
| Message-ID | <[email protected]> |
On Fri, Nov 01, 2013 at 03:29:12PM +0900, Masataka Ohta wrote: > TLS is another PKI and is inherently insecure as CAs can be > compromised. True, but Tony's quorum-based approach could be made exhaustive enough that the adversary would have to have compromised *every* CA. If they can do that, I'm not sure any realistic defense is possible anyway. -- Evan Hunt -- [email protected] Internet Systems Consortium, Inc. _______________________________________________ dnsext mailing list [email protected] https://www.ietf.org/mailman/listinfo/dnsext