4 ms·
Serious question: isn't that how SSL/TLS certificates work too, by chain of trust?
by cocochanel 7y ago
Serious question: isn't that how SSL/TLS certificates work too, by chain of trust?
- majewsky 7y agoYes, but only because every other known solution is worse in practice.
- pornel 7y agoThe infosec definition of trust is not really the same as the colloquial meaning of trust. The infosec "trust" is not something earned or even verified, but an assumption that something is not malicious. Imagine a fortress: inside of the walls is called "trusted", outside of the walls is "untrusted". So a trusted CA merely means a certificate inside your fortress' walls that an attacker can't modify.
- buckminster 7y ago> an assumption that something is not malicious. It's not even that. It's just a statement of fact. The things that you put in positions where they can fuck you are de facto the things you trust. You might know for a fact that they are untrustworthy garbage, but you're still trusting them.
- NohatCoder 7y agoRelatively few companies can sign TLS certificates, and you have the security of the domain name as well. In order for an attacker to steal a TLS session they need to compromise both the certificate system and the dns lookup.
- gruez 7y agoIt also helps that the CAs have an incentive not to get caught (CA death penalty for misissuance)
- perlgeek 7y agoThe trust that browsers place in the TLS chain of trust is basically just the assertion that the holder of the TLS key is the one who owns the domain. This doesn't imply anything about the contents that can be transferred over the TLS connection. Could be malware. The other side could leak your private data like crazy. That's outside the scope of the TLS chain of trust.