Earlier quoted context omitted.
Care to elaborate on DNSSEC? I've been interested in seeing wider adoption of DNSSEC for things like DANE.
DANE is a replacement for the CA system that effectively cedes cryptographic control of most of the Internet to world governments.
DANE can work perfectly fine with the existing CA system to provide another way of verifying that the correct TLS certificate (or CA) is being used. Or... it can be used with a completely different trust anchor or TLS certificate that you control. Your choice.
But you and I will just have to disagree on this topic. Your dislike of DNSSEC is well-known, as is my support for it.