6 ms·
Widely deployed PKI would transform humanity as we know it, and I believe largely for the better (Yelp, Facebook, and many other websites besides would be rende
by leot 13y ago
Widely deployed PKI would transform humanity as we know it, and I believe largely for the better (Yelp, Facebook, and many other websites besides would be rendered irrelevant with widespread PKI). "Like" this restaurant? Sign its public key and give it a star rating.
Want to consult with person X who is trusted by authority Y to do Z at a level L? This is straightforward without a bespoke who-trusts-whom website (heck, it's possible without "users") if we have PKI.
Every year we don't have PKI is quite possibly trillions lost globally. If the NSA has been the one preventing the adoption of widespread PKI, then this is the cost they have imposed.
- Phlarp 13y agoThis is utopian fantasy and will remain utopian fantasy until you can teach my mother how PKI works. For 99% of the population, excel formulas are the pinnacle of their technical prowess.
- leot 13y agoIf I was advocating teaching people to read 800 years ago, you could have said the same thing about literacy. People learn when it's sufficiently important that they do so.
- danabramov 13y agoCan you sell literacy to someone? I think it's fairly simple: if you're literate, you can make way more money for your family. How do you sell understanding cryptography, using it in real life and whatnot?
- a3n 13y agoRight now there's relatively little risk in credit and identity theft, because people are usually mostly made whole after an event. As more criminals pour through the holes opened by the NSA and their ilk, it will become difficult and then impossible for most of those victims to be made whole. At that point you can easily sell security, privacy and good government. That is, if it isn't taken violently at the point of a pitchfork. [Hey, NSA, have you reinforced your buildings?]
- danabramov 13y agoDon't get why you're being downvoted. I can hardly imagine my friends signing restaurants' public keys. They don't have any problem with Facebook or Foursquare whatsoever. As some guy said, you can't start with the technology and work backwards to customer experience.
- danabramov 13y agoAlso, I doubt that decentralized liking is what will render Facebook obsolete. This is a very tech-centric point of view. People don't think of Facebook as of some kind of key-value storage where they can learn who liked what. They use Facebook to share stuff that happens to them with their friends.
- Zigurd 13y agoDid your mother ever use Skype? Then she used a secure system. There are variants on the ideas behind PKI that are easy to use, and that do not rely on centralized trust.
- xyzzy123 13y agoI agree with your general sentiment but we're still not there yet. Unfortunately, Skype hold all your keys and Microsoft changed the architecture to make legal intercept and tapping much simpler. I do not believe it is safe to assume that Skype conversations are private. Current systems really do rely on users having some understanding of how trust in the application works. For example, TextSecure really requires you to confirm keys in person (or via QR code etc) if you want to be sure you are not MITM'd. This is not obvious to most users I have spoken to.
- Zigurd 13y agoReal time communication can use ephemeral keys. A Skype-like communications tool could be open, verifiable, as simple as Skype, and at least as hardened as Skype was before it was castrated. As for web-of-trust for store and forward communication, social networks are an great way to provide secure key-signing.
- xyzzy123 13y agoEphemeral keys, sure. Negotiated with... well... who exactly? The person you thought you were talking to, or someone else? The available solutions are shared secrets with zero knowledge proof (like OTR does), voice verification (like various "secure phones", a web of trust, or CA infrastructure. Crypto everywhere will improve things immensely, but (repeating myself) ultimately the user needs to understand how they can trust that the other party is who they say they are. So far we do not have a magic (automatic) way to do that for the user.
- Zigurd 13y agoUnless NSA has a great Max Headroom version of me, I think people will trust that they are talking to, or listening to me. That's why I wrote "realtime communication." For store and forward you need public key exchange and a mechanism for trusting identity. However, in most use cases where you have a mix of realtime and store and forward communication, you have ample opportunity for key signing where you can trust the identity of the person asking for your signature. tr;dr: There really are no usability excuses.