Can we replace DNSSEC with something that doesn't give government control over root zones?
Can we replace DNSSEC with something that doesn't give government control over root zones?
Repeat after me: rubber hose cryptanalysis is unbeatable / cryptography cannot solve political problems.
Why should a litany of CAs with authority to sign certificates for largely any TLD be preferable to only allow the entity that's authoritative on domain ownership being able to sign valid certificates? DV certs are just indirectly checking with DNS anyways and there are pitfalls in that process and no real benefits in the end.
Neither Google nor Mozilla can revoke .COM, and the USG has repeatedly used its authority over .COM for public policy ends.
If the USG actually did seize control over gmail.com, and they had some CA sign a DV cert for them, how would that constitute a misissuance? The whole point of a DV certificate is that it only attests that the owner of the cert is the owner of the domain. The scenario we're talking about is a government becoming the new owners of a domain name.
But regardless of that, mitigating government overreach by means of having hundreds of sacrificial CAs is a pretty poor solution. What happens if Let's Encrypt gets blacklisted? That's a huge chunk of the internet gone right there until everyone gets around to replacing them. IANA doesn't have to have the root and TLDs delegated to a single entity. DNSSEC could be replaced by something requiring signatures from multiple different entities in multiple different jurisdictions to actually solve this problem. Have the root and global TLDs signed by at least 3 out of 5 entities with no more than 2 of those being from a Five Eyes nation. IANA already has a mediation process to resolve disputes with domain names, there's no reason why legitimate domain seizures couldn't be subjected to that process rather than just a unilateral court order to the registrar.
As for killing large existing CAs though, just look at how egregious Symantec was before Mozilla and Google ultimately decided to pull the plug. For years there'd be new ever more creative ways in which Symantec misissued certificates and their responses always seemed to be some variant of "Sorry, we didn't know we weren't supposed to issue certificates to entities other than the owner". There is still considerable friction to removing misbehaving CAs. As a matter of fact, Symantec in particular did misissue certificates for google.com back in 2015 during that whole test certificate debacle.