4 ms·
I think you are right. At some point system 1 will need to talk to system 3 to validate the message (unless system 1 and 3 have an already shared secret or pub
by codegladiator 7y ago
I think you are right.
At some point system 1 will need to talk to system 3 to validate the message (unless system 1 and 3 have an already shared secret or public key)
- speedplane 7y ago> I think you are right. ... At some point system 1 will need to talk to system 3 to validate the message Yes, this is why any post claiming to "roll their own security" is a farce. The current way security works (using HTTPS) is to pre-install trusted certificates on the machine at the hardware manufacturer or OS installation level. The keys that are pre-installed are this initial high level (usually root certificates), can then secure lower level machines, which can further secure even lower level machines. This only works because we trust our hardware manufacturers (e.g., Dell, HP, etc.) to install the correct certificates. These manufacturers are analogous to "System 3" in the example above.