Earlier quoted context omitted.
how a more robust system might be created and promptly adopted I'm quite fond of how the SSH host key system works. Prompt me the first time I see a new key, provide me with supporting evidence (e.g. show me how many people have previously accepted this fingerprint for this domain) and alert me the same way in the future if the key ever changes. If the 'supporting evidence' was plugin-based then this system could qui…
All interesting ideas... but don't directly address rapid trust revocation , as in the case of recent relevance: a site's private keys are assumed to have been compromised (as if by the heartbleed bug). Or are you suggesting every browser will contact many of its personal web-of-trust sources on every secure-connection? Without additional innovation, that seems just as prone to the performance bottlenecks or soft-fai…
For Hacker News? No.
For my bank? Yes, absolutely.
The implementation of a fast and scalable lookup is not exactly rocket science (cf. DNSBLs). It's a political problem, not a technology problem.