Safari can't verify the identity of the website "blog.easydns.org". The certificate for this website is invalid. You might be connecting to a website that is pretending to be "blog.easydns.org", which could put your confidential information at risk. Would you like to connect to the website anyway?
As usual, misconfiguration causing scary warnings, useless to the end user, but the connection is still encrypted. I really wish we'd divorce the identity assurance part of PKI from the encryption part. I have no idea how it would be done, but.
You have a moral obligation to use crypto
21–30 of 92 posts
Re: You have a moral obligation to use crypto
#22However, here's the deal/problem:
I am willing to encrypt outgoing mail only in cases where I can identify that the recipient are capable of decrypting it (with 0 friction at any stage).
It's (still) more important to me that my e-mail is read by the recipient, than that it's not read by any other party.
Re: You have a moral obligation to use crypto
#23The Internet services who are complaining should start coding, instead, or in addition to complaining. Secure key exchange, secure real time communication, secure storage, and secure email payload would blind the surveillance state. All surveillance states. Even if you think your own surveillance state is less than harmful, there are dozens of others which are patently evil or thoroughly corrupt. And yet, while we do…
Re: You have a moral obligation to use crypto
#24I can't comment on which encryption schemes are still strong, but one advantage to using protection for general use is providing strength in numbers. Right now, using Tor or strong encryption is a bright beacon saying "this person has something to hide!" and the NSA et al hone in by default.
If, however, using Tor and strong encryption was the norm, it is easier for those who need it - whistle blowers, dissidents, etc - to hide underneath the regular noise.
edit: keep getting flagged for spam! Perhaps I have the wrong keywords?
Re: You have a moral obligation to use crypto
#25The Internet services who are complaining should start coding, instead, or in addition to complaining. Secure key exchange, secure real time communication, secure storage, and secure email payload would blind the surveillance state. All surveillance states. Even if you think your own surveillance state is less than harmful, there are dozens of others which are patently evil or thoroughly corrupt. And yet, while we do…
Google has done more to securely encrypt Internet traffic than any other company in the world. Among other things, they are the pioneering standard-bearer for ECC forward secrecy and for certificate pinning, the two most important Internet encryption advances in the last 10 years.
Actually, you can stop being obtuse here rather than farther down the thread.
Re: You have a moral obligation to use crypto
#26Earlier quoted context omitted.
As usual, misconfiguration causing scary warnings, useless to the end user, but the connection is still encrypted. I really wish we'd divorce the identity assurance part of PKI from the encryption part. I have no idea how it would be done, but.
HTTPS Encryption is virtually useless without the identify verification part. Anyone can run a valid HTTPS server with a self-generated public key. Anyone could then place a MITM, and without the identity bit, you're just as compromised. If we had dropped the identity bit, every ISP would be running a MITM proxy, because they want control. Already, plenty of businesses enable poor hygiene by including transparent squ…
Re: You have a moral obligation to use crypto
#27I could understand a moral obligation to fight unjust surveillance, but that is not what was presented. Why am I morally obligated to increase the cost of surveillance? If society accepts the unjust surveillance the only consequences of increasing surveillance costs are economic waste and most likely justifications for new encroachments on personal liberty.
Re: You have a moral obligation to use crypto
#28Never going to get tired of self-identified libertarians making statements about moral obligations.
Re: You have a moral obligation to use crypto
#29Earlier quoted context omitted.
Google has done more to securely encrypt Internet traffic than any other company in the world. Among other things, they are the pioneering standard-bearer for ECC forward secrecy and for certificate pinning, the two most important Internet encryption advances in the last 10 years.
That's nice. But putting our email, IM, and VoIP out of reach of snooping would actually change things. Actually, you can stop being obtuse here rather than farther down the thread.
Re: You have a moral obligation to use crypto
#30Never going to get tired of self-identified libertarians making statements about moral obligations.
I would probably self-identify as a libertarian (although I would be eager to qualify that), and I am very tired of statements about moral obligations.