Live data from Hacker News

Avoiding Internet Centralization

mnot.github.io

11–20 of 111 posts

Re: Avoiding Internet Centralization

#11
Something not really covered is this concept: "Maybe don't let one telecom company acquire too much control".

Look at the history of everything that was acquired by either Qwest/CenturyLink or Level3, and then the merger of Level3. You can't tell me that the existence of Lumen, the combined Centurylink-Level3 entity is good for anyone, except for their shareholders.

It's the very definition of too much centralization.

Look at all of the things that have now been jammed together into the modern Verizon, as well.

Look at the sad state of competition in Canada, with Rogers and Shaw trying to merge.

Re: Avoiding Internet Centralization

#13
post #2

> 5.2. Encrypt, Always: When deployed at scale, encryption can be an effective technique to reduce many inherited centralization risks. ... The problem here is the word "Always". Encryption is good for just the reasons they say. But only encryption, always encryption, not having an option for plain text is highly centralizing in itself. This is because the current status quo for encryption is to use TLS based on cert…

LE also forces you to rely on DNS, which is highly centralized..

Re: Avoiding Internet Centralization

#14
post #3

> Some protocols require the introduction of centralization risk that is unavoidable by nature. For example, when there is a need a single, globally coordinated 'source of truth', that facility is by nature centralized. No, there is nothing unavoidable in making a centralized DNS system.

I think that's a question of whether you're thinking of “unavoidable” in the technical or social context. You could design a system where anyone can run their own root but would you want to operate a business in a world where your advertisements need to list which of the DNS roots you use and spend time paying to register with everything which becomes popular enough that spammers would consider registering your names? That seems even worse than the proliferation of top-level domains since there at least the name which people see is actually different than the one you advertise.

Re: Avoiding Internet Centralization

#15
post #2

> 5.2. Encrypt, Always: When deployed at scale, encryption can be an effective technique to reduce many inherited centralization risks. ... The problem here is the word "Always". Encryption is good for just the reasons they say. But only encryption, always encryption, not having an option for plain text is highly centralizing in itself. This is because the current status quo for encryption is to use TLS based on cert…

LE also forces you to rely on DNS, which is highly centralized..

What CA doesn't?

Re: Avoiding Internet Centralization

#16
post #12

1970: we're going to build an unbreakable worldwide network to survive a nuclear war 2021: AWS and amazon US-EAST-1 is down, this means my coffee maker doesn't work

Source: https://twitter.com/VessOnSecurity/status/146845781929696870...

Added attributed original to https://github.com/globalcitizen/taoup

Re: Avoiding Internet Centralization

#17
post #7
post #6

Earlier quoted context omitted.

Encryption does not imply authentication, does it?

Browsers scaremonger really hard about self-signed SSL certs. And browsers are starting to implement HTTPS only as a default. It won't be too long before HTTP is blocked by mega-corp browsers and not having a CA TLS cert means your website is now un-visitable by non-technical people (and not indexed by search engines).

The concern about http over https is that a bad actor can intercept and change traffic.

If you allow self signed certificates, anyone who can MITM traffic can masquerade your site just like with http

Self signed does however stop passive fibre taps - to intercept you need to MITM.

There then the “remember this cert” option. If I visit www.selfsigned.com on a secure network, my browser remembers the certificate. If I then travel to another network with a MITM, my browser can flag up a warning. This is how SSH works.

However I’m not too concerned by SSL certificates as a centralised point - my browser trusts dozens, probably more than 100, root certificates. That’s not centralisation.

Re: Avoiding Internet Centralization

#19
post #15

Earlier quoted context omitted.

LE also forces you to rely on DNS, which is highly centralized..

What CA doesn't?

I don't think it was meant as a criticism, just a statement of the current status quo, which is inherently rooted in the centralized DNS.

Re: Avoiding Internet Centralization

#20
post #2

> 5.2. Encrypt, Always: When deployed at scale, encryption can be an effective technique to reduce many inherited centralization risks. ... The problem here is the word "Always". Encryption is good for just the reasons they say. But only encryption, always encryption, not having an option for plain text is highly centralizing in itself. This is because the current status quo for encryption is to use TLS based on cert…

LE also forces you to rely on DNS, which is highly centralized..

[deleted]
Post reply on HN