Earlier quoted context omitted.
Correct me if I'm wrong, but haven't you also attacked TOFU POP as being worse than the CA system? If I understand correctly, it was a limited form of TOFU POP that caught this attack. (And it seems like TOFU POP MONK would fix the remaining weaknesses of TOFU POP.)
I think key continuity is an even worse solution for Internet trust than CAs.
Iran forged the wrong SSL certificate
111–115 of 115 posts
Re: Iran forged the wrong SSL certificate
#112Earlier quoted context omitted.
I am not a fan of the HTTPS/TLS CA system. You know I'm not. Yeah, but to 99.99% of people out there, the existing CA system is an integral part of TLS. Every time you tell people to use TLS, you're (inadvertently) encouraging them to trust the certificate authority structure.
No I'm not.
Re: Iran forged the wrong SSL certificate
#113Earlier quoted context omitted.
Chrome has some script-control features built in that I use heavily. What would I gain from a chrome extension?
I can't find anything that provides those features. Can you let us know where it is? (Chrome 13.0.782.112 on Linux)
Re: Iran forged the wrong SSL certificate
#114Earlier quoted context omitted.
I can't find anything that provides those features. Can you let us know where it is? (Chrome 13.0.782.112 on Linux)
settings -> under the hood -> content settings
Why I use NotScripts: the extension lets you enable JS temporarily or permanently for a particular website with just a mouse click. As well, at the same time, you can do the same thing for any third-party JS because it presents you with a list of them. So you can enable jsquery and disable google-tracker at the same time.
It's much easier than navigating the menu system to add an exception to the list of blocked sites for each time you just want to read a PDF, for example. That's the main use-case for me.
Re: Iran forged the wrong SSL certificate
#115Earlier quoted context omitted.
Hell, for DOD systems on secure networks, you're required to remove all of the non-DOD root CAs. No DigiNotar or GoDaddy or the hundreds of others allowed.
DoD systems on secure networks shouldn't have IP connectivity outside DoD, though. The only issue is code signing keys for activex/java. (which really shouldn't exist on DoD secure networks either, but they've fully drunk the MS kool-aid)