3 ms·
Simply because a plugin can be verified locally at length whereas a compromised CA can issue a fake cert that is very, very difficult to detect.
by magikarp 15y ago
Simply because a plugin can be verified locally at length whereas a compromised CA can issue a fake cert that is very, very difficult to detect.
- jbri 15y ago> but the problem is that there exist many users who don't know how to review JavaScript and don't know what a CA is, and will just rely on what their browser tells them (which is where a plugin comes in handy.) > a plugin can be verified locally at length whereas a compromised CA can issue a fake cert that is very, very difficult to detect. Which is it? Either you're claiming that verifying a plugin is easier than not trusting CAs that you don't trust, or you're arguing two completely contrary positions. edit: And this then brings us back to the earlier point, which is why not just use the plugin for crypto in the first place?
- magikarp 15y agoUm, no. The plugin is the same for all users - not everyone who downloads and runs GnuPG knows how to verify it - but some people might go as far as to either compile it from source or ever decompile it. If they find something suspicious, they will report it so that other people who have downloaded the software can be aware. Same thing goes for the plugin (except that the plugin is easier to verify than a compiled binary.) When I talk about people who can't review JavaScript or CAs, I'm talking about the average computer user. I am not saying that "verifying a plugin is easier than not trusting CAs that you don't trust." The average computer user doesn't care about CAs or JavaScript. My point remains: a plugin can be verified by others who have downloaded it - a compromised CA is extremely difficult to detect.
- jbri 15y agoSo once again: > And this then brings us back to the earlier point, which is why not just use the plugin for crypto in the first place?
- magikarp 15y agoI'm sorry, but I've already answered this, as a reply to one of your own comments. Please scroll up.
- fadzlan 15y agoTo that point, what is the difference :- 1. just trusting the cert say for Amazon directly rather than trusting the chain of trust using CA (distrust all the root CA and just trust the cert of Amazon) between 2. Trusting verified Javascript directly.