> are there things we can do right now in terms of favoring self-authentication of self-signed certs?
That's a good question, but I've yet to see any justification for thinking the answer is "yes".
If an attacker controls your network connection and/or DNS, what possible information could you obtain to prove the authenticity of a website, without reference to an external source of authority?
Agreed. That's why it was a question. :) I'm trying to get people to start thinking in that direction, rather than in a central source of authority (which also means DNSSEC or DNS TXT's are out)
That's a good question, but I've yet to see any justification for thinking the answer is "yes".
If an attacker controls your network connection and/or DNS, what possible information could you obtain to prove the authenticity of a website, without reference to an external source of authority?