Earlier quoted context omitted.
> The "logic" behind PKI dictates that it's a third party identifying my bank to me Not true. The third party is an operational detail to scale, there's no reason your bank is less trusted than anyone else to confirm that they're really your bank, are they? You're suggesting that you don't trust your bank's opinion on what websites belong to them, but do trust some third party's? Even if this made any sense, the thir…
there's no reason your bank is less trusted than anyone else to confirm that they're really your bank, are they? Yes, there is. The list of entities I actually care about authenticity for are vanishingly small, basically just financial institutions and CAs themselves (for all other communication I don't trust who I think I'm talking with any more than I would trust a hypothetical man in the middle, so authenticity do…
WoSign and StartCom: Mozilla’s proposed conclusion
131–140 of 252 posts
Re: WoSign and StartCom: Mozilla’s proposed conclusion
#132Earlier quoted context omitted.
OK, so what do you want to happen starting tomorrow morning? * All HTTPS sites show up as trusted. Woohoo! * All HTTPS sites show up as untrusted, people are encouraged to switch to HTTP. Woohoo! * All HTTPS sites use trust-on-first-use, which means that we have a date and time announced when MITM attacks are particularly effective and will persist for a very long time. * All HTTPS sites are untrusted, except for tho…
Mostly #5, with some of #4. We have known bad certs in the wild (including for Google) so the "security" PKI offers us is just theater. I think the theater should end, which might actually get people off their asses to fix the real problem and stop outsourcing it to shady rent-seeking companies.
Re: WoSign and StartCom: Mozilla’s proposed conclusion
#133Earlier quoted context omitted.
there's no reason your bank is less trusted than anyone else to confirm that they're really your bank, are they? Yes, there is. The list of entities I actually care about authenticity for are vanishingly small, basically just financial institutions and CAs themselves (for all other communication I don't trust who I think I'm talking with any more than I would trust a hypothetical man in the middle, so authenticity do…
I am having a really hard time following this argument. The CA isn't vouching for the content of your HTTPS requests.
Re: WoSign and StartCom: Mozilla’s proposed conclusion
#134Earlier quoted context omitted.
Isn't that only E&Y Hong Kong, though? Really at this point I don't know why anybody in China, or any country known for its corruption, should be accepted as auditors.
You're painting 1 billion people with a rather broad brush.
Re: WoSign and StartCom: Mozilla’s proposed conclusion
#135Earlier quoted context omitted.
Mostly #5, with some of #4. We have known bad certs in the wild (including for Google) so the "security" PKI offers us is just theater. I think the theater should end, which might actually get people off their asses to fix the real problem and stop outsourcing it to shady rent-seeking companies.
If the security the CAs offer is "just theater", go spoof DNS and phish Bank of America logins; you should be able to trick users just by rolling self-signed certificates.
Re: WoSign and StartCom: Mozilla’s proposed conclusion
#136Earlier quoted context omitted.
Why are you using S/MIME? You can still get free S/MIME certs from Comodo.
Wasn't Comodo on the list of bad CAs one should avoid too?
Re: WoSign and StartCom: Mozilla’s proposed conclusion
#137Earlier quoted context omitted.
If I might ask, why don't you like them?
They are a political organisation and their ideas conflict with mine. I don't keep a strong boycott on them, but I don't want to support their products, that's all.
Re: WoSign and StartCom: Mozilla’s proposed conclusion
#138Earlier quoted context omitted.
If the security the CAs offer is "just theater", go spoof DNS and phish Bank of America logins; you should be able to trick users just by rolling self-signed certificates.
You do know that BofA is one of the organizations with verified bad certificates in the wild, right? This isn't just a theoretical worry. That's why it's "theater": we know that right now there are valid but bad certificates for a depressing number of entities.
Re: WoSign and StartCom: Mozilla’s proposed conclusion
#139Now that StartSSL is effectively deceased, is there a commercial CA that supports the ACME protocol? Or is the ACME protocol a vanity project unique to Let's Encrypt? I manage several dozen certificates; I was very pleased when StartSSL offered an automated API to work with. Despite their flaws, they offered EV certs, wildcards, and automated one-shots, and it was very convenient. I'd gladly pay for this functionalit…
Our API predates ACME, but we'll most likely be implementing ACME once it's finalized.
Re: WoSign and StartCom: Mozilla’s proposed conclusion
#140Earlier quoted context omitted.
I am having a really hard time following this argument. The CA isn't vouching for the content of your HTTPS requests.
No, the only thing the CA vouches for is that the other party is who they claim to be, which 99% of the time doesn't matter because I don't trust who they claim to be any more than I trust someone impersonating who they claim to be.