12 ms·
If you thought the title was nonsense, it gets worse when the author tries to explain what a certificate authority does: > Websites that want to be designated
by kam 8y ago
If you thought the title was nonsense, it gets worse when the author tries to explain what a certificate authority does:
> Websites that want to be designated as secure have to be certified by an outside organization, which will confirm their identity and vouch for their security. The certifying organization also helps secure the connection between an approved website and its users, promising the traffic will not be intercepted.
- nightfly 8y agoThat is a perfectly reasonable description for a non-technical reader.
- deleted 8y ago[deleted]
- kam 8y agoThe biggest issue with it to me is the "vouch for their security" part, perpetuating the myth that HTTPS means the site is "safe" or that a certificate is a security audit of some kind.
- stordoff 8y agoI'm not a fan of promise - it makes it sound like a choice, and not something enforced by the design (assuming it's set up properly, which the CA _can't_ promise).
- kbenson 8y agoIt's actually not all that wrong, given a very loose and forgiving interpretation of what they mean. Certificate authorities do "help" secure the connection by providing trust by "promising the traffic will not be intercepted" through an exploit in their certificate, and oftentimes insuring the connection to provide this trust (that's a lot of the difference in price between cheap and expensive certs, they insure for more). You could say this helps secure the connection by providing enough assurance that people are then willing to use the connection at all. Welcome to the world of marketing and PR, where loose terminology, ambiguous phrasing means and a little imagination means never having to say you were wrong...
- jarfil 8y agoThat kind of explanation is how a company could "promise the traffic will not be intercepted" while using ROT13 to secure it. Also the insurances/warranties are a joke, the way they're written, there is pretty much no way anyone will be able to ever land a claim against them.
- tialaramex 8y agoYeah, no, it's pretty badly wrong. Sometimes you will see a journalist say something that's just _technically_ wrong, in an "Um... actually" kind of way. Like saying there are 4 billion "Internet addresses". Yeah it's actually 2^32 and those are IPv4 addresses, and anyway some are in reserved classes we can never use and... We shouldn't care about these cases, it's fun to make a big deal as a _nerd_ but it's not a real problem. But here they are misleading people as to the general purpose of a CA. The CA doesn't in fact promise "traffic will not be intercepted" and how could they. The CA promises that their subscriber proved to them that they know a private key to which the corresponding public key is in the certificate, and that they control the things (usually FQDNs) named in the certificate. Insurance, as another poster points out, is basically worthless. In fact it's worthless in multiple independent ways, it's deliberately engineered to _be_ worthless. For consumer insurance that would be illegal in many countries (taking people's money to "insure" against a risk that won't happen is prohibited in those countries), but they don't sell it to consumers, they sell it to the Certificate Authority and non-individuals are more free to make bad decisions since nobody important will get hurt.
- matthewmacleod 8y agoThe CA doesn't in fact promise "traffic will not be intercepted" and how could they. The CA promises that their subscriber proved to them that they know a private key to which the corresponding public key is in the certificate, and that they control the things (usually FQDNs) named in the certificate. Right, but surely you see how 90% of that statement is utterly incomprehensible to a general audience?
- tialaramex 8y ago