3 ms·
The "What Problem Do Certificates Solve" paragraph is a little bit confusing. The role of a certificate is to ensure integrity and confidentiality of communicat
by ajnin 2y ago
The "What Problem Do Certificates Solve" paragraph is a little bit confusing. The role of a certificate is to ensure integrity and confidentiality of communications between two hosts. The "making sure the certificate holder is who they claim" part is the role of the CA authority hierarchy, which interestingly is a system based on some hard math but also mostly on trust, authority, and everyone's ability to keep keys private.
- robxorb 2y agoAs a total newcomer expecting to have the use of certificates explained, that section lost me at this point: > However, the hacker somehow obtains a certificate issued to super-bank.com If the article is to explain the use, it might be good to explain first what they are. As it immediately circularly referenced certificates as if they're a concept the reader already understands, I couldn't learn anything from it.
- crabbone 2y agoDon't worry, several sections in, after couple of (clumsy) metaphors trying to explain what certificates are for, the author suddenly remembers that: > To Themselves: Protect the private key of their root certificate. Oh, there are also keys! Apparently, private (but maybe also public). I, too, find this explanation to be poorly thought out. I generally don't like it when an explanation has to resort to metaphors in order to explain something: it usually generates more questions as to the extent of the applicability of the metaphor. ---- While I do have to use certificates in less trivial ways than just firing up the browser, I cannot comprehend some design choices that went into building this contraption. Not to mention the abysmal quality of the libraries implementing the relevant functions as well as abysmal quality of documentation to accompany it. I'm not expert enough to point to the exact problems, or offer better solutions though...
- layer8 2y agoNo, the role of a certificate is to certify that a given entity is the owner of the private key associated withe the public key you see. Its role is similar to an ID card (which certifies that the pictured person is the one named on the card). You don’t need certificates to ensure the integrity and confidentiality of communication. Cryptographic keys alone already do that job. What certificates do is ensure that the peer you’re confidentially exchanging integrity-assured messages with is really the one you think it is, based on a third party (the CA) whose key you already trust. As a physical-world analogy: A sealed envelope ensures the integrity and confidentiality of a letter. But it doesn’t tell you who really sent the letter. If, however, the seal (think of a wax seal) was made with a stamp, and you have a government document (certificate) that tells you that this stamp belongs to person X, then you have assurance about who sent the letter.