In Certificate Transparency, a CA is responsible for sharing its issued certificates to CT. In Key Transparency, anyone can register a key for an email address; they just have to arrive first. Is there any provision for preventing squatting ?
Security Through Transparency
11–20 of 41 posts
Re: Security Through Transparency
#12This is also useful for understanding some of the core differences between CONIKS and Key Transparency - https://github.com/google/key-transparency/blob/master/docs/...
Re: Security Through Transparency
#13The post mentioned the inadequacy of PGP. I would like to see a comparison with Keybase ( https://keybase.io ) which addresses similar problems.
You don't need to do anything and you get encryption and trust and all that stuff.
While keybase is a step in the right direction, it does not make communication any more secure by default.
You still need to setup PGP and use it to benefit from keybase.io
So in essence; CT is that one step ahead of keybase.io that makes it much much more useful but keybase is still a step in the right direction.
Re: Security Through Transparency
#14Re: Security Through Transparency
#15The post mentioned the inadequacy of PGP. I would like to see a comparison with Keybase ( https://keybase.io ) which addresses similar problems.
CT is mostly an automagic comparison. You don't need to do anything and you get encryption and trust and all that stuff. While keybase is a step in the right direction, it does not make communication any more secure by default. You still need to setup PGP and use it to benefit from keybase.io So in essence; CT is that one step ahead of keybase.io that makes it much much more useful but keybase is still a step in the…
Re: Security Through Transparency
#16So everytime you want to communicate you ping Google's servers?
Re: Security Through Transparency
#17So everytime you want to communicate you ping Google's servers?
First, like CT you want an ecosystem of logs.
Second, you have caching and in-band exchanges as means to mitigate some of that.
Re: Security Through Transparency
#18So everytime you want to communicate you ping Google's servers?
I didn't see any evidence of them suggesting that.
Get a /service account key/ and download the generated JSON file.
The service account key is used to verify client OAuth tokens.
/from here:/ https://console.developers.google.com/apis/credentials