3 ms·
The big reason that cert's are as unused as they have been for two decades is because of the stupid desire to incorporate identity along with encryption. They'
by dethswatch 10y ago
The big reason that cert's are as unused as they have been for two decades is because of the stupid desire to incorporate identity along with encryption.
They've both useful- they've more useful together, and they're expensive and not used everywhere because of the identity problem.
This is just going to have to be accepted (for a while?) to get proper encryption.
Pointing out that this can happen is neither useful or news, and perpetuates this nonsense that's been holding us back.
- gcp 10y agostupid desire to incorporate identity along with encryption. It's not a stupid desire. Encryption is pretty useless without authentication.
- SomeStupidPoint 10y agoI think they mean lack of tying two notions of identity together: domain name and "real world" entity. DV certs tie encryption to a purely digital identity while EV ties that identity to a real world identity as well.
- ubernostrum 10y agoThe average blogger cares that their password is encrypted when logging in to their blog. They probably don't care very much whether someone can also verify their legal identity, and in fact quite a few bloggers probably explicitly don't want that. The average banker, on the other hand, does care about the identity verification. Why have we decided that everyone must have the banker's use case?
- eridius 10y agoDV doesn't do legal identity. It does domain verification. And that's exactly what your blogger wants. A secure connection without domain verification means you can be trivially MitM'd.