16 ms·
I don't understand why a protocol with known major problems that can be compromised by oppressive governments is a better solution to client-side crypto that ca
by magikarp 15y ago
I don't understand why a protocol with known major problems that can be compromised by oppressive governments is a better solution to client-side crypto that can be verified for integrity and hides the plaintext from the server.
- jbri 15y agoTLS encryption can't be compromised by oppressive goverments. Only the CA-based authentication can. Trying to "fix" this by rolling your own ad-hoc encryption (while ignoring the authentication issue entirely) is completely missing the point.
- tptacek 15y agoOnly the configuration of the CA-based authentication can. Nobody loves X509 PKIs, but so far, they seem to "work". This matters because you can literally write a HOWTO that my mom could follow to get a browser configured so that China can't snoop on (many of) your HTTPS connections. No code required.
- tptacek 15y agoThe protocol doesn't have known major problems.