logoalt Hacker News

fc417fc802today at 1:17 AM1 replyview on HN

Well yes, CAs and the ICANN model of DNS are intertwined and fundamentally broken in multiple ways. However the system as a whole is largely "good enough" as can be seen from its broad success under highly adversarial conditions in the real world.


Replies

rerdaviestoday at 9:40 AM

That's not really how security works. Either it's broken, or it's not. Security is only as good as the weakest link in the chain. Whether it's good enough or not... hard to say.

show 1 reply