91 ms·
Irony. HTTPS deployment in China is going very ... not bad. First and second tier websites already switched it on long ago. Because in China we had an ancient
by rqs 8y ago
Irony. HTTPS deployment in China is going very ... not bad.
First and second tier websites already switched it on long ago. Because in China we had an ancient tradition for ISPs to sniff and modify user's traffic to (for example) inject their own affiliation codes to the web request. Those websites hates it of course.
- taneq 8y agoAnother example of how "untrusted by default" results in a better system.
- forkerenok 8y ago> Irony. HTTPS deployment in China is going very ... not bad. Given Chinese govt has been controlling some CAs, China vs. HTTPS irony is.. well, less of an irony :)
- rqs 8y agoOn the "CAs is controlled by state" side, some privacy enthusiasts in China already removed those CAs from their system long ago. Go give them some hug and support: https://github.com/chengr28/RevokeChinaCerts https://github.com/chengr28/RevokeChinaCerts And of course, in the context of CA, what's truly important is transparency in the audit process and continuous monitoring. Catch them red handed will end their business[0] once and for all. And so far, most of them are rule-abiding. [0] https://blog.mozilla.org/security/2016/10/24/distrusting-new-wosign-and-startcom-certificates/ https://blog.mozilla.org/security/2016/10/24/distrusting-new...
- gsnedders 8y agoAnd it's a question of when, and not if, we require CT logs for every certificate the browser sees.