
what is the thing with DNS? why is it 2 thin slabs?
DNS is held up by a surprisingly small number of root servers. Their physical locations are not disclosed.
No what? The geographical locations for all 13 root " servers" and who manages them are well known (the only problem is the US is in charge of all of them). The actual number of physical servers is significantly greater. Actual requests are serviced using IP Anycast and can scale significantly better than connection-oriented services.
Misconfiguration is the bigger issue. Dnssec is not easy to get right, while caching makes things harder to fix immediately.
Seems like we could at least get rid of the sharks.
“Quantum-Safe” means that whatever mistakes happen with these TLS certificates, a kind-hearted time traveler will zap into our bodies to fix them for us.




