Earlier quoted context omitted.
Yes: assume one of the thousands of CAs you trust has been compromised by NSA.
Okay, so this is what happens: 1. Evil NSA compromises CA in BFE 2. Evil NSA subverts DNSSEC for COM to publish a bad CA certificate 3. Some combination of Google Certificate Transparency + HPKP discovers this, the CA in BFE gets removed from browsers If your point is "DNSSEC is pointless", OK. But it sounds like you're saying it makes us less secure. I'm just trying to figure out how that could even be.
http://sockpuppet.org/blog/2015/01/15/against-dnssec/
... or its FAQ.