Earlier quoted context omitted.
Maybe I'm missing your answer there ... You just say: Still there is good reason that browsers rub it in the users face when a site tries to use a self-signed certificate but I don't see where you say what that good reason is. If a self-signed cert is more secure than plain HTTP, why make a self-signed cert more painful to use than plain HTTP?
Because with HTTP, there is no assumption of security at the side of the user, or at least there shouldn't be. With HTTPS (and the "lock symbol") there is. The people that really know what they're doing can click through the warnings and still do what they want. But casual users that assume https=safe have the chance to leave. I'm all for deprecating HTTP the same way they did with TELNET, and warning the user for ev…
Linus Torvalds Interview for LinuxFR
21–30 of 57 posts
Re: Linus Torvalds Interview for LinuxFR
#22For someone who is not a native English speaker, Linus really has an awesome way with words.
Re: Linus Torvalds Interview for LinuxFR
#23Because ethics are to me something private. Whenever you use it as an argument for why somebody_else should do something, you're no longer being ethical, you're just being a sanctimonious dick-head. For someone who is not a native English speaker, Linus really has an awesome way with words.
Edit: OTOH, Linus is talking in the context of software licenses -- I agree with him that it can get holier-than-thou the way some folks push the GPL (not least its original author).
Re: Linus Torvalds Interview for LinuxFR
#24Because ethics are to me something private. Whenever you use it as an argument for why somebody_else should do something, you're no longer being ethical, you're just being a sanctimonious dick-head. For someone who is not a native English speaker, Linus really has an awesome way with words.
One can very well use it as an argument for why somebody else should or should not do something. e.g: One should not throw a hard-disk at Linus Torvalds because they might hurt him and that's just wrong...
Re: Linus Torvalds Interview for LinuxFR
#25Earlier quoted context omitted.
Because with HTTP, there is no assumption of security at the side of the user, or at least there shouldn't be. With HTTPS (and the "lock symbol") there is. The people that really know what they're doing can click through the warnings and still do what they want. But casual users that assume https=safe have the chance to leave. I'm all for deprecating HTTP the same way they did with TELNET, and warning the user for ev…
The browser could just not show the "secure" visuals, instead of making us click through another page.
This is the right workflow you should follow with self-signed certificates, it is similar to SSH. You need to accept the certificate once. After manually verifying it is the right one, you're even more secure than trusting on a CA...
Re: Linus Torvalds Interview for LinuxFR
#26Earlier quoted context omitted.
Granted, it doesn't provide as much protection as a cert signed by a trusted CA - but it's still far more protection than plain HTTP, right? e.g, Firesheep wouldn't work I don't know if browsers do this, but in principle they could even notify the user on certificate change, so the MITM would have to be on the first connection to a site.
Introducing a "third state" for the SSL indicator, usability-wise, is very difficult. A lot of browser users don't understand SSL, and those that do have a binary understanding of the protocol: it can be used to either confirm or refute the identity of a website. It's very difficult to implement a UI for the regular users that says: "this might be a MITM attack since I cannot confirm the identity of the site but at l…
Re: Linus Torvalds Interview for LinuxFR
#27Earlier quoted context omitted.
The browser could just not show the "secure" visuals, instead of making us click through another page.
Well, the warnings are only shown once. Once you import the self-signed certificate into your keystore, it never bothers you again (unless the certificate changes). This is the right workflow you should follow with self-signed certificates, it is similar to SSH. You need to accept the certificate once. After manually verifying it is the right one, you're even more secure than trusting on a CA...
Your statements about what should happen are only true if you are requiring encryption for everything that you do. On the web, it's assumed (although most people don't actually know this) that your information is not secure unless you see the green bar or whatever the security visual is on your particular browser.
This brings me back to smanek's point. We have three levels of security: no SSL, untrusted cert, trusted cert. Nothing about the first level is superior to the second level, except for the possibility of a false sense of security. Therefore, a browser should not freak out more in the second situation.
Re: Linus Torvalds Interview for LinuxFR
#28Because ethics are to me something private. Whenever you use it as an argument for why somebody_else should do something, you're no longer being ethical, you're just being a sanctimonious dick-head. For someone who is not a native English speaker, Linus really has an awesome way with words.
Re: Linus Torvalds Interview for LinuxFR
#29Because ethics are to me something private. Whenever you use it as an argument for why somebody_else should do something, you're no longer being ethical, you're just being a sanctimonious dick-head. For someone who is not a native English speaker, Linus really has an awesome way with words.
He doesn't have a way with words unless "being rude" now means "having a way with words". Furthermore, his statement is logically incorrect (the best kind of incorrect): the sense of right and wrong is a general human trait, independent of race or culture. It can be altered by nurture, but it transcends it. One can very well use it as an argument for why somebody else should or should not do something. e.g: One shoul…
If you're talking about the fact that every culture has notions of right and wrong, yeah sure.
If you're saying that what is right and what is wrong is universal and not cultural ... Well where to begin
Some of thoses traits are shared amongst most cultures (Murder is wrong, incest is wrong), but even there there are exceptions (ritual murder ?). For anything more complicated than that, this position is simply impossible to hold.
Most precisely, about property, intellectual or physical, and things like profit, the sense of right and wrong varies so wildly amongst cultures that i can't really think you're making this argument seriously.
Re: Linus Torvalds Interview for LinuxFR
#30Because ethics are to me something private. Whenever you use it as an argument for why somebody_else should do something, you're no longer being ethical, you're just being a sanctimonious dick-head. For someone who is not a native English speaker, Linus really has an awesome way with words.
At least it's clear what he's saying, but I was surprised at this -- it puts Linus well and truly in the postmodern camp. He says ethics are completely relative and personal. (Which of course is not the case: if I try to kill someone, the cops aren't being "sanctimonious dick-heads" when they stop me.) Anyway, all this is off topic, but I was just surprised at Linus's relativism when he seems so "absolutist" about ma…
So it's as easy to find something we all mostly agree on (murder) than something we all mostly disagree on (property).
Also taking the murder example is quite dishonest. Linus wasn't talking about murder issues. He was talking about intellectual property issues. Do you claim there is objective right and wrong in this domain ? Do you claim to know what it is ?
EDIT : Didn't see your edit, so correction about the "dishonest argument" part :)