Live data from Hacker News

It’s Time to Encrypt the Entire Internet

wired.com

31–40 of 99 posts

Re: It’s Time to Encrypt the Entire Internet

#31
post #5

So perhaps this should start with a reduction in the cost of valid, "don't throw a security warning" certificates down to zero. At the moment the SSL certificate industry is one big ripoff fest...

> So perhaps this should start with a reduction in the cost of valid, "don't throw a security warning" certificates down to zero.

And then people will complain that the CA is not required to revoke certificates that it issued for free when their keys become compromised.

What is people’s idea of DANE? DNSSEC adoption seems slow at the moment, but otherwise it appears to be a valid approach to this whole distributing-public-keys issue?

Re: It’s Time to Encrypt the Entire Internet

#32
post #10

It's time to decentralize the internet. There is no good reason why we can't have email, webpages, photos, even facebook-like social stuff housed on our own machines in our own homes (or some other place under our control). The current situation is akin to having to travel to some centralized letter-reading facility in order to read letter mail. Your grandma sends you a letter in the mail and you have to go to a cent…

Decentralization is absolutely necessary, it's just completely counter to the way the economy on the Internet currently works. SAAS falls apart if everyone is hosting their own stuff, let alone the do it for free and sell ads in it model. Unless people are willing to start paying software developers directly en masse for decentralized locally run versions of products we currently get for free it isn't going to happen…

It's funny isn't it. The current state of affairs and the direction we're moving in reminds me (since I'm old enough to remember) of the early days of server based computing and dumb terminals. VAX's in some room somewhere and DEC terminals for the people. Now it's google server farms and chromebooks

Re: It’s Time to Encrypt the Entire Internet

#33
post #26
post #10

It's time to decentralize the internet. There is no good reason why we can't have email, webpages, photos, even facebook-like social stuff housed on our own machines in our own homes (or some other place under our control). The current situation is akin to having to travel to some centralized letter-reading facility in order to read letter mail. Your grandma sends you a letter in the mail and you have to go to a cent…

> It's time to decentralize the internet. There is no good reason why we can't have email, webpages, photos, even facebook-like social stuff housed on our own machines in our own homes (or some other place under our control). This is how the internet is designed, and you can already do this today. In my case, I host my own dns, email, and my own webpages, locally on my home connection. You just have to be willing to…

Why would you need your own DNS?

Re: It’s Time to Encrypt the Entire Internet

#34
post #30
post #25

Earlier quoted context omitted.

> It's time to decentralize the internet. There is no good reason why we can't have email, webpages, photos, even facebook-like social stuff housed on our own machines in our own homes (or some other place under our control). I think there is a good reason. Who wants to spend the time setting up and running a server? I happen to run my own, but it is definitely not something I would recommend to my friends and family…

"Maybe someone will come along and create a super easy to install and low maintenance server platform" that's the idea

How would you ensure operational continuity for my mom who only has an ipad? Since that's the direction the world seems to be taking.

Re: It’s Time to Encrypt the Entire Internet

#35
post #26
post #10

It's time to decentralize the internet. There is no good reason why we can't have email, webpages, photos, even facebook-like social stuff housed on our own machines in our own homes (or some other place under our control). The current situation is akin to having to travel to some centralized letter-reading facility in order to read letter mail. Your grandma sends you a letter in the mail and you have to go to a cent…

> It's time to decentralize the internet. There is no good reason why we can't have email, webpages, photos, even facebook-like social stuff housed on our own machines in our own homes (or some other place under our control). This is how the internet is designed, and you can already do this today. In my case, I host my own dns, email, and my own webpages, locally on my home connection. You just have to be willing to…

>This is how the internet is designed, and you can already do this today. In my case, I host my own dns, email, and my own webpages, locally on my home connection. You just have to be willing to learn, and willing to do. Once you've learned, the actual "do" is rather trivial.

That's great that it works for you. But there are lots of people who are perfectly capable of doing this who don't want the hassle (let alone the huge numbers of people for whom this is completely impossible). I spent most of my youth screwing around with computers and learning a lot about how all this stuff works and it was great fun. Now that I'm getting older, it is frankly growing tiresome. The last thing I want to do on a Saturday-- when I should be playing with my kids and enjoying life-- is fuss with some file server that is acting up, preventing my wife from posting vacation photos. I've got enough work to do around the house so as it is. I don't need to be on call 24/7 for IT infrastructure support.

Re: It’s Time to Encrypt the Entire Internet

#36
post #26
post #10

It's time to decentralize the internet. There is no good reason why we can't have email, webpages, photos, even facebook-like social stuff housed on our own machines in our own homes (or some other place under our control). The current situation is akin to having to travel to some centralized letter-reading facility in order to read letter mail. Your grandma sends you a letter in the mail and you have to go to a cent…

> It's time to decentralize the internet. There is no good reason why we can't have email, webpages, photos, even facebook-like social stuff housed on our own machines in our own homes (or some other place under our control). This is how the internet is designed, and you can already do this today. In my case, I host my own dns, email, and my own webpages, locally on my home connection. You just have to be willing to…

So I'm looking at moving my VPS into a box at home, but I have an IP that changes every so often. What's the best way to fix that? I've got no problems with DNS being hosted on Route53 or something else.

Re: It’s Time to Encrypt the Entire Internet

#37
post #25
post #10

It's time to decentralize the internet. There is no good reason why we can't have email, webpages, photos, even facebook-like social stuff housed on our own machines in our own homes (or some other place under our control). The current situation is akin to having to travel to some centralized letter-reading facility in order to read letter mail. Your grandma sends you a letter in the mail and you have to go to a cent…

> It's time to decentralize the internet. There is no good reason why we can't have email, webpages, photos, even facebook-like social stuff housed on our own machines in our own homes (or some other place under our control). I think there is a good reason. Who wants to spend the time setting up and running a server? I happen to run my own, but it is definitely not something I would recommend to my friends and family…

> Maybe someone will come along and create a super easy to install and low maintenance server platform.

There is a developer release available already: https://freedomboxfoundation.org/ All packages are included in Debian Sid.

Re: It’s Time to Encrypt the Entire Internet

#38
post #9

Yet when I go to this link it's plain HTTP.

Wired just got it wrong postfixing https instead of prefix :) http://www.wired.com/2014/04/https/ But to stay on topic: encouraging this kind of major shift to SSL spreads a problem that is still there but is very little acknowledged or worked on -- revocations. Certificate revocation check is using either CRL or OCSP. CRL is a list of all the revoked certificates - browser needs to download the whole file and then c…

However, it seems possible to explicitly use a secure browser (i.e. one that checks certificate revocations) if the need arises. You don’t need 99% browser-market coverage to allow people to securely connect to your site, nor do you need 99% browser-market coverage to securely connect to a given site. You only need that site to implement HTTPS, either with a self-signed cert and e.g. Certificate Patrol on your side or a CA-signed cert and a revocation-checking browser. In the latter case, you should also configure your browser to consider an OCSP failure an invalid certificate, not a valid one.

Re: It’s Time to Encrypt the Entire Internet

#39
post #10

It's time to decentralize the internet. There is no good reason why we can't have email, webpages, photos, even facebook-like social stuff housed on our own machines in our own homes (or some other place under our control). The current situation is akin to having to travel to some centralized letter-reading facility in order to read letter mail. Your grandma sends you a letter in the mail and you have to go to a cent…

There is good reason: it's bad for software businesses.

Even if you had a turnkey solution (it doesn't exist yet) to self-host emails & stuff, the companies selling it wouldn't be able to get good search engine rankings.

The web giants have no interest in solutions that don't require them to host your data (so they can serve you advertising or hosting plans). Even small shops are usually based around a Service As A Software Substitute (SaaS) business model and don't give a crap about you not depending on them when you start their application.

Re: It’s Time to Encrypt the Entire Internet

#40
post #36
post #26

Earlier quoted context omitted.

> It's time to decentralize the internet. There is no good reason why we can't have email, webpages, photos, even facebook-like social stuff housed on our own machines in our own homes (or some other place under our control). This is how the internet is designed, and you can already do this today. In my case, I host my own dns, email, and my own webpages, locally on my home connection. You just have to be willing to…

So I'm looking at moving my VPS into a box at home, but I have an IP that changes every so often. What's the best way to fix that? I've got no problems with DNS being hosted on Route53 or something else.

Just use one of the multitude of dynamic dns providers.
Post reply on HN