5 ms·
How would you possibly know which fingerprints to trust? Also, do you honestly think there is any hope for the average user to understand what that means and kn
by conorgil145 9y ago
How would you possibly know which fingerprints to trust? Also, do you honestly think there is any hope for the average user to understand what that means and know what to trust and what not to trust? IMO, that is a massive step backwards in usability, which directly impacts the overall security of a given solution. If something is not usable, then people will figure out a way around it and security then goes out the window.
For example, if users were responsible for knowing which fingerprints to trust for a given website, they would most likely just click "ok, trust it" for everything. Then, you're overall security goes way down because now people are conditioned to click "accept" to everything, regardless of the impact.
- dredmorbius 9y agoSigned archives of trusted or untrusted fingerprints, distributed by various and independent authorities is one option. Trust is, by definition, an extention of solidity or support. CA is a trust model, which has proved both brittle and unworkable. http://www.etymonline.com/index.php?term=trust&allowed_in_frame=0 http://www.etymonline.com/index.php?term=trust&allowed_in_fr... Google and other services presently provide extended trust and validity assessments for websites: pinned certificates, malware scans, and the like. A limited number of such reliable schemes would scale reasonably well, and should prove useful. I'm not saying "perfect", I'm saying "useful".
- topranks 9y agoDANE perhaps? http://www.internetsociety.org/deploy360/resources/dane/ http://www.internetsociety.org/deploy360/resources/dane/
- dredmorbius 9y agoInteresting, that's a possibility. I was thinking of something more akin to, say Google's pinned certificates (something which practices such as Let's Encrypt actually makes harder AFAICT): https://security.stackexchange.com/questions/29988/what-is-certificate-pinning#29990 https://security.stackexchange.com/questions/29988/what-is-c... Or something that might be a parallel of email reputation services -- SenderBase / IronPort (now Cisco) rating email servers by their spam loads, etc. Rather than negative reputation, a positive reputation (vouch rather than warn) might be viable. (Negative ratings systems, digital or otherwise, tend to inspire various legal assaults.)