> Forging a ‘fake CT log’ isn’t possible, either
Why do you think this isn't possible?
Why do you think this isn't possible?
CT logs are used by CAs, not clients. A 'fake' log isn't a thing.
(Not that I'm a DNSSEC user myself, my feet aren't bulletproof)
Particularly when the software in question is running on somebody else computer, proprietary software and OS (or OS modules), unknown patch versions, etc.