I never find this kind of stuff funny... it's more snark than humor. It's also got a weird racial tinge on the tiresome trope of a somewhat distrustful middle eastern laborer, which makes it gross.
Add Honest Achmed's root certificate (2011)
21–29 of 29 posts
Re: Add Honest Achmed's root certificate (2011)
#22I never find this kind of stuff funny... it's more snark than humor. It's also got a weird racial tinge on the tiresome trope of a somewhat distrustful middle eastern laborer, which makes it gross.
How is he somewhat distrustful? He’s Honest Achmed, it’s right there in the name. And the application is certainly very honest.
Re: Add Honest Achmed's root certificate (2011)
#23Seems quite racist to me using the stereotype of the middle eastern shady used cars dealer? Do we want such content here (I'd say no)?
> Seems quite racist to me So if it was Honest John you would be okay with that? > Do we want such content here (I'd say no)? You have 'flag' and 'downvote' buttons for this.
Re: Add Honest Achmed's root certificate (2011)
#24Classic of the genre. I remember around the time of the diginotar horrors looking at DANE and DNSSEC. As I understand it, DANE still isn't supported by browsers, and DNSSEC is still in a pitiful state.
Re: Add Honest Achmed's root certificate (2011)
#25Seems quite racist to me using the stereotype of the middle eastern shady used cars dealer? Do we want such content here (I'd say no)?
> Seems quite racist to me So if it was Honest John you would be okay with that? > Do we want such content here (I'd say no)? You have 'flag' and 'downvote' buttons for this.
Re: Add Honest Achmed's root certificate (2011)
#26I never find this kind of stuff funny... it's more snark than humor. It's also got a weird racial tinge on the tiresome trope of a somewhat distrustful middle eastern laborer, which makes it gross.
When all you have is a hammer, everything looks like a nail.
Also, there's a lot of racist nails lying around, so being a nice strong anti racist hammer is not the worst thing I've been accused of.
Re: Add Honest Achmed's root certificate (2011)
#27Earlier quoted context omitted.
> Seems quite racist to me So if it was Honest John you would be okay with that? > Do we want such content here (I'd say no)? You have 'flag' and 'downvote' buttons for this.
I don't think there's a downvote button for posts.
Re: Add Honest Achmed's root certificate (2011)
#28Classic of the genre. I remember around the time of the diginotar horrors looking at DANE and DNSSEC. As I understand it, DANE still isn't supported by browsers, and DNSSEC is still in a pitiful state.
DANE is even worse than the CAs in this regard. Nobody trusts the CAs, so they all have to record all their issuances in a transparency log. If a CA misissues, the browsers will kill it (as has happened with some of the largest CAs). There's no way to revoke a misissued DNSSEC signature and there's no transparency log for DNSSEC, nor will there ever be, because the browsers can't force DNS registries to implement it…
Another day in tech, another deep sigh.
Re: Add Honest Achmed's root certificate (2011)
#29For a long time, I've argued we need leaf certificates to be double signable. That way there can be two chains of trust for a website. Then dropping a CA doesn't matter much, since all serious parties should have multiply signed paths to various roots of trust. Hence we solve the problem of CAs becoming to big to fail. The current way cross-signing works is almost an accident, and only works for intermediate certific…
I see what you meant--having two for redundancy--but I was much more excited by the idea of having two where both had to be valid, as getting two organizations to issue you a bogus certificate is going to be a hell of a lot harder than getting one (not impossible, but often an entirely different kind of attack). Maybe we require three and at least two have to be valid, providing the benefits of both angles? ;P