Reply to post: Re: You can't trust anybody

Chinese CA hands guy base certificates for GitHub, Florida uni

Lee D Silver badge

Re: You can't trust anybody

There's no reason that website's can't crytographically sign a message in DNS that tells you what CA's are valid for them.

In fact there are protocols for exactly that.

Done properly, even the people who control DNS can't interfere (they can only "break" the chain, which is obviously visible).

But nobody has ever sat down and fixed email either, and that's much more important.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon