logoalt Hacker News

tptacekyesterday at 4:03 PM0 repliesview on HN

That's one way to put it. Another way to put it is that the CA system keeps cryptographic trust managed by organizations that can easily be destroyed if they fail, while DANE's trust is practically irrevocable.