The only long term solution here is a distributed decentralized DNS service. When there's "default-trust" at some locations (browser CAs), There's weak-points in the security chain.
What are the best available dDNS solutions. Ideally these are initially backward compatible with redular DNS to help adoption, and then just disregard CAs.
Imagine your regular developer performing a npm install which pulls in code from a compromised MITMed github URL. That's straightforward rootkit compile and install access!
The only long term solution here is a distributed decentralized DNS service. When there's "default-trust" at some locations (browser CAs), There's weak-points in the security chain.
What are the best available dDNS solutions. Ideally these are initially backward compatible with redular DNS to help adoption, and then just disregard CAs.