3 ms·
Are you sure that the agencies you speak of are not able to do this anyway? Even the Hong Kong Post Office has a place among the trusted CA's supplied by most v
by voidz 12y ago
Are you sure that the agencies you speak of are not able to do this anyway? Even the Hong Kong Post Office has a place among the trusted CA's supplied by most vendors: not really necessary for everyone on the planet, I'd think. If even just one of those trusted CAs would or has become compromised, all bets are off. Which has already happened in the past anyway.
So, how you defend "SSL everywhere".. I don't buy it. I feel more for what the commenter you responded to said, because your counter argument comes with a lot of assumptions that have more problematic implications. A false sense of being secure does seem much worse than knowing that most of the stuff you do is actually insecure to begin with.
Plain text is not a bug. It's a feature! Cheesy, I know.
- yourad_io 12y ago> A false sense of being secure does seem much worse than knowing that most of the stuff you do is actually insecure to begin with. It may feel so, but it certainly isn't. Some security (against anyone but the top 0.X% of "bad guys") is certainly better than no security (random script kiddie in your coffee shop injecting 0-days from exploit-db straight to your browser). And regarding the hopelessness of SSL/TLS - the CA problem exists and is pretty huge. But we know the solution[1]: it's called certificate pinning. When you control clients (Google/Chrom[e/ium]) can just pin your own certs/CA and refuse anything signed by the Hong Kong office. For the rest of us that don't, there's HSTS (to tell the browser to refuse http:// http:// redirects from a MiTM, overriding TLS altogether) and Public Key Pinning Extension (HPKP). They aren't very widely rolled out, but we're getting there. Test your browser here[2], you may be surprised. This all assumes that the user won't ignore the warnings when they come up, of course. Also it would protect you from your second visit onwards - if you're being MiTM'ed at your first attempt to grab a site with all the above bells and whistles, your browser doesn't know about the pinned stuff yet, so it is vulnerable to SSL stripping, etc. In short, it's certainly better than nothing (protecting you from 99%+ of bad guys) and we're slowly fixing it[3]. Don't let the man get you down. [1] Until we get to a proper, more distributed solution [2] https://projects.dm.id.lv/Public-Key-Pins_test https://projects.dm.id.lv/Public-Key-Pins_test [3] Shamefully slowly - TACK was proposed so long ago... https://news.ycombinator.com/item?id=4010711 https://news.ycombinator.com/item?id=4010711
- voidz 12y agoAlright, useful to consider. Thanks.