Live data from Hacker News

Launching in 2015: A Certificate Authority to Encrypt the Entire Web

eff.org

471–476 of 476 posts

Re: Launching in 2015: A Certificate Authority to Encrypt the Entire Web

#471

This certificate industry has been such a racket. It's not even tacit that there are two completely separate issues that certificates and encryption solve. They get conflated and non technical users rightly get confused about which thing is trying to solve a problem they aren't sure why they have. The certificate authorities are quite in love that the self-signed certificate errors are turning redder, bolder, and big…

Wasn't WOT (Web Of Trust) supposed to fix this? Basically, I get other people to sign my public key asserting that it's actually me and not someone else, and if enough people do that it's considered "trusted", but in a decentralized fashion that's not tied to "authorities"?

Re: Launching in 2015: A Certificate Authority to Encrypt the Entire Web

#472
post #60

This certificate industry has been such a racket. It's not even tacit that there are two completely separate issues that certificates and encryption solve. They get conflated and non technical users rightly get confused about which thing is trying to solve a problem they aren't sure why they have. The certificate authorities are quite in love that the self-signed certificate errors are turning redder, bolder, and big…

> A self signed certificate warning means "Warning! The admin on the site you're connecting to wants this conversation to be private but it hasn't been proven that he has 200 bucks for us to say he's cool" no. It means "even though this connection is encrypted, there is no way to tell you whether you are currently talking to that site or to NSA which is forwarding all of your traffic to the site you're on". Treating…

The solution, at least for something decentralized, seems to be a web of trust established by multiple other identities signing your public key with some assumption of assurance that they have a reasonable belief that your actual identity is in fact represented by that public key.

That's what PGP/GPG people seem to do, anyway.

Why can't I get my personally-generated cert signed by X other people who vouch for its authenticity?

Re: Launching in 2015: A Certificate Authority to Encrypt the Entire Web

#473
post #396

Earlier quoted context omitted.

You're saying that everyone able and willing to passively snoop, is also able and willing to compromise the channel and mimic the server?

Correct.

Then I don't see how that would be true. Mimicking a server requires significantly more effort that simply storing the traffic. So even if someone were able, it doesn't follow that they would want to go through that effort in every case.

Re: Launching in 2015: A Certificate Authority to Encrypt the Entire Web

#474

This certificate industry has been such a racket. It's not even tacit that there are two completely separate issues that certificates and encryption solve. They get conflated and non technical users rightly get confused about which thing is trying to solve a problem they aren't sure why they have. The certificate authorities are quite in love that the self-signed certificate errors are turning redder, bolder, and big…

> 200 bucks for us to say he's cool

There are trusted free certificates as well, like the ones from StartSSL.

> if a bank pays 10,000 bucks for a really cool verification, they get a giant green pulsating URL badge

Yeah, $10 000 and legal documentation proving that they are exactly the same legal entity as the one stated on the certificated. All verified by a provider that's been deemed trustworthy by your browser's developers.

Finally, if a certificate is self-signed, it generally should be a large warning to most users: the certificate was made by an unknown entity, and anybody may be intercepting the comunication. Power-users understand when self-signed CAs are used, but they don't get scared of red warnings either, so that's not an issue.

Re: Launching in 2015: A Certificate Authority to Encrypt the Entire Web

#475

Earlier quoted context omitted.

An NSL can be used only to compel release of connection or transaction metadata, and cannot be used to compel disclosure of message contents. It's basically a fast-track for getting things like call records, and it most emphatically cannot be used to compel turning over a certificate or allowing a man-in-the-middle. To my knowledge the exact details of the Lavabit case were never released, but from what has been rele…

Okay, so not an NSL. Incorrect terminology pointing at the same awful effect, an unaccountable court issuing unchallengeable rulings that cannot be discussed. No substantial difference from the concept I'm complaining about.

"Ignorance more frequently begets confidence than does knowledge."

Re: Launching in 2015: A Certificate Authority to Encrypt the Entire Web

#476
post #175

Earlier quoted context omitted.

> non-profit domain registrar domain squatters are already an issue. imaging if you could register domains for free. I think having to pay $10 for a year is pretty fair. That's one reason I don't mind paying ~$70 for .io domain. it keeps most squatters away.

You misunderstand. Domains must not be free, and domain cost isn't the problem. Nonprofit registrar != free domains. The problem is the horrible user experience of registrars like Godaddy. I'd rather give my money to a nonprofit that isn't confusing non-technical website owners into buying products they don't need. The registrar landscape is better now with Gandi, but still I'd rather pay a fully transparent nonprofi…

Sorry, I did misunderstand. Completely agree.
Post reply on HN