Since companies are competing, it would be hard to find an
organization that everyone would trust to manage the KDC.
Whoever manages the KDC can access every user's master key, and
therefore access everything that every user can access.
• Furthermore, that highly trusted entity would also be a busy one,
having to process all instances of users and services joining and
leaving the network.
• Even if there were an organization everyone was willing to trust,
this is not enough. Everyone must also trust the physical controls
around every replica of the KDC, and there would have to be widely
dispersed replicas to ensure availability and convenience.
Compromise of any replica, no matter how obscurely placed it was,
would yield everyone's keys