4 ms·
Maybe he is saying by removing trusted root certificates he will trade the possibility of receiving a fraudulent certificate the first time he uses a site for t
by arg01 13y ago
Maybe he is saying by removing trusted root certificates he will trade the possibility of receiving a fraudulent certificate the first time he uses a site for the possibility of not being warned if a certificate changes because the trusted roots are compromised. If he needs to worry about state actors there is an argument to be made for this trade-off, but really if he was worried about that he would be delivering certificates out of band and not visiting any unknown websites on the machine he needed that level of security on. (Maybe justifiable against mass surveillance where you're a general target rather than a specific one).
- cortesoft 13y agoYes, verifying certs out-of-band is most likely more secure than a CA. I was not counting that in the self-signed cert vs CA signed cert comparison, since that is not what most people mean when they talk about a self-signed cert.
- arg01 13y agoYou ignored my first point. You can trust the self signed certificate to be used by the same entity(A or C) after the first connection, admittedly you may have been MITM (by C) for that first time(and renewal times) and because of that you may be screwed. Alternatively if you are trusting other entities(B) to verify the certificate of A while B are not trustworthy then after that first communication (even if that first communication was legitimate) another entity (C) can pretend to be A and so long as B verifies C then you are in trouble. I am pointing out that they are different risks and I agree that in nearly all use cases it is better to use verified certificates than self-signed for general internet use, that doesn't mean that there isn't a reason to do otherwise though.
- icebraining 13y agoThere are extensions to warn you about certificate changes even if the new is signed by a CA, so that's a terrible reason.
- euank 13y agoAh, yes, certificate patrol[0]. However, your argument, I think, is not valid. Sure, it's technically possible for him to know if any cert changes, but in reality very few people are going to install the extension and those that do might not even notice the message because it notifies the user so frequently (fully desensitizing them I imagine). I don't think that his choice not to install an extension invalidates his argument. [0]: https://addons.mozilla.org/en-us/firefox/addon/certificate-patrol/ https://addons.mozilla.org/en-us/firefox/addon/certificate-p...
- icebraining 13y agovery few people are going to install the extension My argument is, pinning certs is a bad reason for removing the root certs from the browser, since you can pin them without breaking the CA chains. I'm not sure how does that work as a counter-argument; We're discussing a decision of a particular person, not some broad policy. How is the number of people who install the extension relevant? those that do might not even notice the message because it notifies the user so frequently (fully desensitizing them I imagine) So does the browser, if you remove the root CA certs.