Doporučuji přečíst ještě výbornější článek for DNSSEC:
Relevantní část:
The "government controlled PKI" criticism ignores the fact that traditional TLDs are a government controlled naming system. This is much worse than a government controlled PKI because Gaddafi could have just taken over Bit.ly directly.
The only way to escape governmental control is to use overlay networks, like Tor, and non-traditional TLDs, such as .bit and .p2p. But even if you choose a domain with a TLD that isn't controlled by a government, you still need DNSSEC to securely delegate to a nameserver and to communicate application level cryptographic information.