4 ms·
As you can see, there is a lot of trust that is given to CAs. The whole cert security depends on it. The only (current) real remedy is the nuclear option - re
by cgtyoder 12y ago
As you can see, there is a lot of trust that is given to CAs. The whole cert security depends on it. The only (current) real remedy is the nuclear option - removing those CA's certs from the major browsers. Then the other side (Chinese browser vendors) can retaliate, of course. So negotiation is required to maintain detente.
- itistoday2 12y ago> The only (current) real remedy is the nuclear option Blockchain-based solutions like Namecoin & DNSChain would have prevented this attack without forcing people to rely on untrusted third-parties (if Google stored their domain info in a blockchain). We compare various mechanisms here: https://github.com/okTurtles/dnschain/blob/master/docs/Comparison.md https://github.com/okTurtles/dnschain/blob/master/docs/Compa... EDIT: Not sure why this comment is getting downvoted. Maybe some folks don't want this problem to be fixed? :-\
- nosuchthing 12y agoDerivatives of Moxie Marlinspike's Convergence cert plugin that allows you to assign your own trust authorities for verifying signatures. [0] [0] https://github.com/moxie0/Convergence/network https://github.com/moxie0/Convergence/network
- itistoday2 12y ago> Derivatives of Moxie Marlinspike's Convergence cert plugin that allows you to assign your own trust authorities for verifying signatures. [0] The only derivative of Convergence that actually addresses the problems with Convergence (ironically), is FreeSpeechMe, which btw, relies on Namecoin's blockchain. But downvote me again for pointing out facts. lol.
- tptacek 12y ago"Downvote me again for pointing out facts" is the "wake up sheeple" of nerd message board discussions.
- ryan-c 12y agoIf Google stored their domain info in a blockchain how would anyone know what identifier actually belonged to Google? The last time I brought this up you admitted there was no good solution yet, has that changed?
- nickodell 12y agoI don't think DNSChain is a feasible project. However, we can reduce the scope of the problem, and just focus on forcing certificates to be public. [1] If we went a bit further, and required that the certs be in the public log for some minimum amount of time (say 6 hours), that would have made it possible to shut down MCS before they got started. [1] http://www.certificate-transparency.org/ http://www.certificate-transparency.org/
- itistoday2 12y ago> I don't think DNSChain is a feasible project. If you want to prevent MITM attacks, it's one of the only options available to you (probably the only realistic option): https://github.com/okTurtles/dnschain/blob/master/docs/Comparison.md https://github.com/okTurtles/dnschain/blob/master/docs/Compa... > However, we can reduce the scope of the problem, and just focus on forcing certificates to be public. [1] DNSChain/Blockchains already provide certificate transparency (publicly auditable log of certs issued), and they do a far better job of it than Certificate Transparency.
- nickodell 12y ago>DNSChain/Blockchains already provide certificate transparency (publicly auditable log of certs issued), and they do a far better job of it than Certificate Transparency. Better in what way?
- itistoday2 12y agoWe wrote a blog post to answer this question: https://blog.okturtles.com/2015/03/certificate-transparency-on-blockchains/ https://blog.okturtles.com/2015/03/certificate-transparency-...