3 ms·
With tools like these out there, what can we do to protect ourselves? Besides not downloading binaries over HTTP (which still wouldn't protect you if a CA has
by Simucal 12y ago
With tools like these out there, what can we do to protect ourselves? Besides not downloading binaries over HTTP (which still wouldn't protect you if a CA has been compromised) what other steps can someone take? I hate how vulnerable and yet utterly essential our browsers have become.
- allegory 12y agoShip the public key by post like internet banking in the early 2000s. This is actually how OpenBSD operates. If you buy an official CD set, the thing ships with keys which are then used to sign downloaded packages. When the keys go via a side channel, the probability of compromise decreases considerably.