4 ms·
Centralized trust is the mechanism used by the current version of the web. It is a broken system by design. Who says I can trust verisign or any other CA. Russi
by 0ldskool 5y ago
Centralized trust is the mechanism used by the current version of the web. It is a broken system by design. Who says I can trust verisign or any other CA. Russia creating their own CA and asking it to be installed just emphasize how broken the current mechanisms are. Its not new, its always been broken.
- randomhodler84 5y agoIt’s a lot more complex than you may realize. We have a transparency solution known as Certificate Transparency. For a “verisign” issued cert to be trusted in the browser, there must be an append only record of the cert stored in a blockchain. If Russia overrides a local trusted root, all bets are off an CTlog is not used. You can trust the CA because malicious issuance is a death sentence. And we have logs for all eternity.
- 0ldskool 5y agoHmm I had never heard of Certificate Transparency, looks like its a relatively newish tech added onto how SSL/TLS certs work. It seems only Google Chrome & Safari require SCT chains (not used by Firefox). Maybe I've never heard of it because I'm a Firefox user? You mentioned blockchain, does that mean there is a public blockchain for these Certs? I didn't see that mentioned anywhere but it does seem like blockchain features overlap with the desired features of "Certificate Transparency".
- aaomidi 5y agoThere is a blockchain ran by a bunch of interested third parties for CT, yes. The block chain is different for each CT operator, it just allows you to validate the issued certs.