> Instead of being able to forge google.com certificates by exploiting any CA on the planet, you suddenly have to exploit either .com TLD nameservers, or google.com nameservers . . . which is going to be close to impossible in either case.
What about country TLDs? If a government wants to do a MITM attack, it can surely control the country-level nameserver.
Posted Mar 25, 2011 13:59 UTC (Fri) by foom (subscriber, #14868)
[Link]
But at least then it's *only* that government for that TLD that can MITM the sites under their TLD, instead of the governments of every single country in the world...