sorry if asking stupid questions...
sorry if asking stupid questions...
Importantly: if NSA is part of your threat model, the hoped-for alternative that STS supersedes --- DNSSEC --- is no help. NSA controls the DNSSEC roots.
and we will have to start writing public keys on a distributed wall of TLDs
Is this any more true than saying "NSA controls the web CA roots" i.e. the NSA could infiltrate one of the hundreds of certificate authorities that browsers trust and issue a malicious certificate?
If so, and if NSA is part of your threat model, then I would say that STS doesn't help very much either.
What's more interesting is the issue of transparency. Are STS clients going to be requiring that the certificates for the HTTPS resources they access are present in a certificate transparency log? CAs are allowed to issue certificates that aren't logged, for privacy reasons I suppose, but there would be no such excuse for a "DNS transparency" log of DNSSEC keys for top level domains. Logging all of these keys would be orders of magnitude simpler than logging all CA issued certificates on the web.
No they don’t. You know better than to spread FUD, regardless of what you think about DNSSEC.
I agree with your other points, however.