Could you please elaborate?
Could you please elaborate?
What you want to prove to yourself is that if "google.com" is associated with public key "04cafebabe", that association is also visible to everyone else (provided other people follow the same protocol).
The distributed DNS+SSL protocol could look like this (simplified):
1) To register a name "google.com", check that it's not registered yet (see below). If not, create a special Bitcoin transaction ("registration tx") that encodes both the name and the public key of the SSL certificate used by that server.
2) To check who owns the name "google.com", find the earliest "registration tx" on the blockchain (other people could add more, but only the first one is considered valid). If the name is 100 blocks deep, trust the public key associated with it.
The protocol can (and should be) extended to allow transferring the name to new public keys, you may check how Namecoin does it.
What you get in result is that every single user can be sure that they see the same up-to-date public key identifying "google.com" without any trusted Certificate Authorities who have failed at this promise multiple times already.
As a nice side effect, name allocation and trade is also decentralized. If you own name "google.com" and users respect the protocol, no one can take this name from you or censor your sale of that name to someone else. Also, you are free to register your own name without asking for anyone's permission and paying fees.
It is not correct.
If I monitor DNS changes, and when new host names pop up. If I have the resources I can make a block-chain transaction automatically.
How will my transactions (provided I also create a new walletID) for each transaction be framed as fraudulent? Without community or authoritative over-site?
I was not saying that new system must necessarily map current DNS owners to new DNS 2.0 owners. These could exist in parallel. My point is to have secure "TLS with names" you must have something like what I describe, otherwise it's a waste of time. Social issues of fairness etc are secondary to the security of addressing names and servers. (Although, they could be real obstacles to adoption, I don't deny that.)
But using namecoin with DNS allows for duplicate and erroneous entries in one or the other. (DNS record != Namecoin record).
Currently most namecoin advocates pretend the former is the case. And it isn't, because have DNS currently. Namecoin is a complete re-invention of the system. Not a iterative improvement.
My issue is that in its current state one can make a namecoin entry that is correct as far as namecoin is concerned, and incorrect as far as DNSSEC or standard DNS is concerned. Thus rendering the system in a weird state.