Where Did DNSSEC Go Wrong? Can potential design pitfalls inform efforts to make DNSSEC more operator-friendly?