HNHacker News
TopNewBestAskShowJobs

moquilabs

4 karma · joined June 10, 2026

submissionscomments
moquilabs··on Aws.com and google.com don't have DNSSEC enabled
Fair point.

I'm just looking for a way to cryptographically prove that my website is from me in a way that browsers will accept.

This means the whole chain from ICANN -> Verisign -> registrar -> dns -> IP -> my server.

moquilabs··on Aws.com and google.com don't have DNSSEC enabled
In the FAQ of this article it says:

> What’s the alternative to DNSSEC? > Do nothing. The DNS does not urgently need to be secured.

> All effective security on the Internet assumes that DNS lookups are unsafe.

This is not true, our entire infrastructure of ACME certificate authorities like let's encrypt are fundamentally dependent on DNS: https://letsencrypt.org/how-it-works/#domain-validation

Then TLS verifies the domain with the private key the certificate authority issues...

How can you trust the s (secure) in https then??

Can anyone provide an example of "effective security on the Internet"?