1. I sign my domains and generate a DS record.
2. I upload the DS record to my registrar who passes the DS record up to the .COM registry.
Now, when someone does DNSSEC validation on my DNS records, they wind up doing this process:
1. Going through the DNS process to get my DNS records as well as the DNSKEY and RRSIGs.
2. Following the chain of DS records up to the .COM registry and on up to the root of DNS... being able to validate along the way the integrity of the records.
Where do world governments get to interfere here?
If a govt were able to manipulate the TLD registry the best they could do would be to point my domain to some other name servers that weren't mine... is THAT the attack you see? I seriously would like to understand.