Live data from Hacker News

Ask HN: Looking for someone to help create a trusted CA

news.ycombinator.com

31–40 of 43 posts

Re: Ask HN: Looking for someone to help create a trusted CA

#31

Earlier quoted context omitted.

It is all nonsense until money is involved and customers want to know that the advertised website actually belongs to your legal entity.

Does not help in any real way. See https://arstechnica.com/information-technology/2017/12/nope-... for an example.

There's a huge difference between "it isn't impossible to bypass" and "does not help in any real way".

Re: Ask HN: Looking for someone to help create a trusted CA

#32
Ignore anyone telling you that what you propose is technically difficult. It is not.

The code for what you want to do has been baked into Windows Server since 2008. It also exists in OpenSSL.

The CA part is easy. The “getting the world to trust your CA” is the part most would call “difficult”.

If you can do the latter, ALOT of people here can do the former, and you will likely succeed.

If you cannot do the latter, you will likely fail in the effort.

Re: Ask HN: Looking for someone to help create a trusted CA

#33

Earlier quoted context omitted.

Does not help in any real way. See https://arstechnica.com/information-technology/2017/12/nope-... for an example.

There's a huge difference between "it isn't impossible to bypass" and "does not help in any real way".

The only reason to get EV certs is the supposedly "safe" green organization field. As demonstrated it can be circumvented by anyone with minimal monetary motivation. Why even bother in that case? I rate that as "does not help in any real way".

Re: Ask HN: Looking for someone to help create a trusted CA

#34

Earlier quoted context omitted.

There's a huge difference between "it isn't impossible to bypass" and "does not help in any real way".

The only reason to get EV certs is the supposedly "safe" green organization field. As demonstrated it can be circumvented by anyone with minimal monetary motivation. Why even bother in that case? I rate that as "does not help in any real way".

> As demonstrated it can be circumvented by anyone with minimal monetary motivation. Why even bother in that case?

Same goes for the lock on your door. Why do you bother? Just take it off.

Re: Ask HN: Looking for someone to help create a trusted CA

#36
post #32

Ignore anyone telling you that what you propose is technically difficult. It is not. The code for what you want to do has been baked into Windows Server since 2008. It also exists in OpenSSL. The CA part is easy. The “getting the world to trust your CA” is the part most would call “difficult”. If you can do the latter, ALOT of people here can do the former, and you will likely succeed. If you cannot do the latter, yo…

The CA part is incredibly easy if you don’t need to consider security.

The difficulty then ramps up the more secure you want (or need) it to be.

Re: Ask HN: Looking for someone to help create a trusted CA

#37

Earlier quoted context omitted.

The only reason to get EV certs is the supposedly "safe" green organization field. As demonstrated it can be circumvented by anyone with minimal monetary motivation. Why even bother in that case? I rate that as "does not help in any real way".

> As demonstrated it can be circumvented by anyone with minimal monetary motivation. Why even bother in that case? Same goes for the lock on your door. Why do you bother? Just take it off.

I never said that. The alternative isn't no lock of course. It's the free lock that's equally safe to the one with the green "this is safe" sticker that you pay a premium for.

Re: Ask HN: Looking for someone to help create a trusted CA

#38

Earlier quoted context omitted.

> As demonstrated it can be circumvented by anyone with minimal monetary motivation. Why even bother in that case? Same goes for the lock on your door. Why do you bother? Just take it off.

I never said that. The alternative isn't no lock of course. It's the free lock that's equally safe to the one with the green "this is safe" sticker that you pay a premium for.

You do realize the "lock" in this analogy that you claimed "does not help in any real way" is the EV, not the encryption?

Re: Ask HN: Looking for someone to help create a trusted CA

#39

Earlier quoted context omitted.

I never said that. The alternative isn't no lock of course. It's the free lock that's equally safe to the one with the green "this is safe" sticker that you pay a premium for.

You do realize the "lock" in this analogy that you claimed "does not help in any real way" is the EV, not the encryption?

I'm not going to continue this argument as it seems pointless. There's a reason Chrome and others moved away from prominently showing EV properties:

https://chromium.googlesource.com/chromium/src/+/HEAD/docs/s...

Re: Ask HN: Looking for someone to help create a trusted CA

#40

Earlier quoted context omitted.

You do realize the "lock" in this analogy that you claimed "does not help in any real way" is the EV, not the encryption?

I'm not going to continue this argument as it seems pointless. There's a reason Chrome and others moved away from prominently showing EV properties: https://chromium.googlesource.com/chromium/src/+/HEAD/docs/s...

There most certainly was a reason, just not your reason (circumvention). Read the page you linked to. It literally says "users did not notice it", "users do not notice their absence", "users do not react as intended to positive or neutral security UI". It was user-focused. Not attacker-focused.

But I do agree it's pointless to keep continuing this.

Post reply on HN