3 ms·
I prefer SSL termination on the client-side (my computer, my data only). I like to have the ability to view my SSL traffic in plain text. Should the user be a
by yp_master 13y ago
I prefer SSL termination on the client-side (my computer, my data only).
I like to have the ability to view my SSL traffic in plain text.
Should the user be able to see what her computer is sending out? I think she should. And encrypted traffic should not be some special exception.
Installing someone else's "MITM" software to decrypt SSL seems unnecessary.
It is much simpler to generate and install your own "fake" certificates that you control.
stunnel is one option.
There are others. socat, Pound, etc.
It should be the user who has the final decision over which certificates to trust. Users are the real "Certificate Authorities". They should have full control over encryption and decryption should they want to exercise it.
Is it wise to irrevocably delegate the decision to trust/not trust to website owners and browser authors? Perhaps those promoting solutions like "TACK" should give this more thought.
- jlgaddis 12y ago> It should be the user who has the final decision over which certificates to trust. Users are the real "Certificate Authorities". They should have full control over encryption and decryption should they want to exercise it. And they do. I'm not sure what you're getting at here. You and I and my mother all have the ability to edit the root CA certificates on our computers and add our own, if we wish.
- yp_master 12y agoIndeed, that has been my solution. But I'm seeing more and more authentication information being incorporated ("baked in", pre-installed, whatever) into browsers, whether it is lists of "valid" TLD's, certificates for "approved" CA's, or chosen individual website certificates. Personally, I think this information should be cleanly separated from the software that may use it rather than pre-installed and "hidden from the user".