5 ms·
If you have evidence, I'm sure you can bring to the attention of the Mozilla Root Store Inclusion program and the CA/Browser forum. Moreover, "there are other c
by stevewatson301 4y ago
If you have evidence, I'm sure you can bring to the attention of the Mozilla Root Store Inclusion program and the CA/Browser forum. Moreover, "there are other criminals who have gotten away with much more" is not an argument.
- yonixw 4y agoI think the steel man version of the argument is: "You showed that there is no effective monitoring or transparency that me as a user can get, and as such, Where is the trust come from. What fundamentally causes Mozilla (or any) to trust CAs more than randomly distributed certificates."
- stevewatson301 4y agoThe CA/Browser forum's requirement and enforcements such as this one (and against DarkMatter, CNNIC and the likes) give me the required confidence to trust them, even though I'd agree it's not a perfect process. Your average user is unlikely to begin to understand why a CA would be trustworthy, and a web of trust model only works for social situations but not for certificate distribution.
- tremon 4y ago"A moose once bit my sister. Therefore all meese must be sacked". I have trouble seeing this as a steeled version of anything. "People have uncovered a flaw in the system, therefore the entire system is unfit for purpose" does not really make a compelling argument. It displays selection bias, hasty generalization, nirvana fallacy, and something about babies and bathwater.
- FeepingCreature 4y agoIf people have "uncovered a flaw", but there is reasonable expectation that the flaw is very widespread and broadly ignored, then there is a reasonable suspicion that the flaw is being weaponized in this case. This is why in many legal systems it is in fact a valid defense to note that the law you are being prosecuted under is not being broadly applied, implying state caprice and corruption.
- yonixw 4y ago> uncovered a flaw in the system I will argue it is not the a flaw in some random aspect of the system, but the main propose of the system. Which is to vet companies they trust to distribute it through CA signing. Do you think I will buy from a restaurant after finding they had expired food? Good food is the reason I'm there in the first place.
- pas 4y agoCAA records and CT logs work, do browsers check them? I know nobody likes DNSSEC, but DANE works too :)
- Avamander 4y agoDANE works on the assumption that DNSSEC is secure, but it's just an another PKI that's way worse and less transparent.
- xorcist 4y agoHow so? DNSSEC is a PKI that follows DNS delegation, and no CA can issue certificates out of scope by definition. That alone should be enough to consider it a strictly better subset of the browser CA PKI model.
- Avamander 4y ago> DNSSEC is a PKI that follows DNS delegation, and no CA can issue certificates out of scope by definition. Sure, and with that you are forced to trust your name servers (and/or the registry's) and your TLD's and the roots'. All that with little choice in the matter, and little to no transparency into the process. Just one example - if your TLD leaks their keys, that's sufficient to forge all the replies a middleman would need and nobody would really notice. With WebPKI you can use CAA records and Certificate Transparency logs, plus you can get some extra assurance from the fact that they have to comply with the policies set by independent trust stores. > That alone should be enough to consider it a strictly better subset of the browser CA PKI model. It's a subset that leaves out the parts that would make it better than WebPKI. Right now it just complements WebPKI, at best.
- pas 4y agoIt's cryptographically signed. it can be validated. browsers can implement it if they wish. I mean it's not like you need it for every HTTP request, or not like DNS is slow. yes, there are potential risks. keys can be leaked. just as in any other scenario.
- radicalbyte 4y agoNo I don't have evidence - however logical deduction shows that the probability of this happening is high. Any system involving humans is fallible, so it would be naïve to think that it doesn't happen. Or put another way: if I was the NSA or MI5 this is exactly how I would attack the problem of traffic interception or targeted black ops. Get a puppet CA via hook or crook. Totally agree that "there are other criminals who have gotten away with much more" is not an argument; I'm not sure what that has to do with my comment? I'm certainly not suggesting that. If anything I suggest that such systems are pretty much broken by design (at least if you care about state actors / extremely well funded actors).