4 ms·
If you go down this path you argue desktop browsing https is broken, which i dont think is a serious argument.
by technion 6mo ago
If you go down this path you argue desktop browsing https is broken, which i dont think is a serious argument.
- quesera 6mo agoNo one is trying to go that far down the path. https (specifically the CA chain of trust) is imperfect, and can be compromised by well-placed parties.
- fc417fc802 6mo agoWell yes, CAs and the ICANN model of DNS are intertwined and fundamentally broken in multiple ways. However the system as a whole is largely "good enough" as can be seen from its broad success under highly adversarial conditions in the real world.
- rerdavies 6mo agoThat's not really how security works. Either it's broken, or it's not. Security is only as good as the weakest link in the chain. Whether it's good enough or not... hard to say.
- fc417fc802 6mo agoThat sort of reasoning only applies to algorithms - those shatter the way glass does. Other stuff is more pliable. It's entirely possible to shoplift but there's a nonzero chance you'll get caught. Is the supermarket's security broken? There are many known attacks against it so I'd say that it is. Notice my wording above - fundamentally broken in multiple ways - by which I mean that there are clear and articulable flaws with the model. Nonetheless it's clearly quite functional in practice.