@a @mwl @colin Cryptographically impossible (assuming the cipher isn't broken which isn't a realistic threat).
Where compromises like the one you cited happen are by compromising one party in the cryptographic chain, not by breaking the crypto. With DANE the only parties who can potentially be compromised are your registrar, the TLD authority, and the DNS root.