Can we leverage signed DNS records to add another layer of control needed? Do we also need encrypted DNS where we can choose who to trust? Are we stuck with the CA trust model?
Can we leverage signed DNS records to add another layer of control needed? Do we also need encrypted DNS where we can choose who to trust? Are we stuck with the CA trust model?
Certificate Transparency. Current browsers are moving to not trust any certificate whose issuance wasn't publicly logged. That doesn't prevent an attacker from issuing an MITM certificate, but doing so would permanently burn a CA. (At least, once the policies are in place and enforced.)
If Verisign deliver a certificate with the wrong domain, you'll be able to know that Verisign signed that certificate.
They could certainly say it was a mistake somewhere in the process, but that argument won't work for ever.
At one point sadly you need to trust someone. This model at least give you a way to prove that trust has been broken.
Site owners can monitor these logs for rogue certs issued for their own domains.