Why? Because DNSSEC can be attacked by the DNS root?
It seemed to be our best attempt to get SSL for every website. CA-based certificates just won't cut it.
It seemed to be our best attempt to get SSL for every website. CA-based certificates just won't cut it.
(I doubt this is what's held up DANE; rather, the unreliability of DNS compared to hyper-optimized HTTPS/TLS connections is the issue there; browser vendors care about milliseconds.)