[0]: https://www.youtube.com/watch?v=JmjRhmk800U
"Governments have agendas, and agendas change" "We may not be perfect, but the safest hands are still our own"
61–67 of 67 posts
[0]: https://www.youtube.com/watch?v=JmjRhmk800U
"Governments have agendas, and agendas change" "We may not be perfect, but the safest hands are still our own"
I'm no fan of the existing system of CA - in 2023 we should have certificate pinning for sites with mechanism for checking which certificate hashes are valid for which site (via a distributed ledger or via browser vendors etc). However this amendment is disgusting. I was one of the many experts reviewing previous drafts; the timing and content of these changes are absolutely an attempt by security services to break s…
Earlier quoted context omitted.
DNSSEC is a great concept with a rather convoluted design that's based on limitations of computers in the 90s. It's obviously better to have DNSSEC than not to, but I wouldn't call it a "great solution". Case in point: the DNS client never actually validates the DNSSEC signatures, the DNS server the client uses is supposed to do that, and then simply sets a flag that says "I validated this". Perfect for recursive DNS…
> It's a shame, really, because DANE would've fixed so many problems. It would basically make services like Let's Encrypt unnecessary and would move us close to a world where email encryption and validation works by default.
DNSSEC sucks ass.
Earlier quoted context omitted.
We're already all used to running ad/script block on our clients so accept a certain level of breakage. It's just a part of the cost of using the web that some sites are crap (youtube being the big one nowadays) but in the end we just "route around them" (they die).
> We're already all used to running ad/script block on our clients so accept a certain level of breakage. The "we" reading this post? Yeah, probably. The internet population as a whole? Absolutely not, nowhere close. I've been using Adblock or its descendants since the original Firefox extension where downloadable filter lists were a separate addon, and every time I have to browse a mainstream web site when using a "…
BUT to be clear the governments shouldn’t be compromising the security of their own people and organisations in the first place. We can’t technology our way out of this behaviour!
Earlier quoted context omitted.
HPKP was generally not recommended even when it was still around due to the danger of breaking your site. https://scotthelme.co.uk/im-giving-up-on-hpkp/
We're already all used to running ad/script block on our clients so accept a certain level of breakage. It's just a part of the cost of using the web that some sites are crap (youtube being the big one nowadays) but in the end we just "route around them" (they die).
My comment was about the perspective of the website owner, not the website user. The website owner certainly doesn't want to be routed around and have the website die. So the website owner will avoid HPKP.
This would be really easy to detect. Just look at the certificate chain. It would be trivial to make a plugin to warn the user of this, at which point they know they're under surveillance which would be worse than just doing human surveillance IMO.
I say this with the upmost request to their politicians, but their politicians have no clue what they're doing. They clearly don't understand how any of this works. None of what they propose can solve the issues they claim they want to solve. Not this, not client-side scanning, nothing. I genuinely wonder who's "advising" them on this stuff and what their true motives are.
It's sad to see the EU like this but nothing lasts forever. I feel sad for the next generations. They'll be the ones to bare the full brunt of these misguided regulations.