logoalt Hacker News

markhahnyesterday at 5:44 PM1 replyview on HN

I'm always mystified why we haven't leveraged DNS.

I mean: why not have cookie policy set by a flag in DNS? Not unlike DKIM or even SSHFP.

Of course, we wouldn't need the entire certificate industry if we simply looked up a site's PK along with its DNS record...


Replies

ambigious7777yesterday at 9:44 PM

You're talking about DAME (which email uses). It has it's own issues like not having transparency logs, and if a DNSSEC signing keyholder goes rogue, there is no easy way to revoke trust (unlike CRLs for Web PKI).