4 ms·
>it should be replaced with something more like bitcoin. What does that even mean?
by coderdude 12y ago
>it should be replaced with something more like bitcoin.
What does that even mean?
- feld 12y agoit doesn't mean anything; just another parrot
- giovani 12y agoHe was probably talking about the centralised model used with CAs, and trying to start a discussion about an alternative to the CA model, probably some way of decentralised control, hence the bitcoin reference. Convergence [1] comes to mind. [1] http://convergence.io/ http://convergence.io/
- dheera 12y agoI would be in favor of decentralised as well; nobody should have to pay money to some bunch of trolls just to use encryption; this is a friction point for a lot of newcomers to web development. In fact, making HTTPS free to use would probably be the best thing that could ever be done for cybersecurity for mankind. Make it zero-friction over HTTP, somehow. Perhaps Google might want to sponsor this? :)
- giovani 12y ago> In fact, making HTTPS free to use would probably be the best thing that could ever be done for cybersecurity for mankind I guess we'll eventually get there, but unless we get decentralised I don't see how it could be done.
- minot 12y agoLet's encrypt works on the assumption that there is no reason why https certificate cannot be easy (not as cumbersome?) to use AND free of cost. They hope to start availability in the middle of this year. Free of cost is possible. We just need to make it easy, reliable, and repeatable for domain name owners to prove their ownership. https://letsencrypt.org/ https://letsencrypt.org/
- outworlder 12y agoFor the time being, use CloudFlare. They have SSL enabled even in the free plan.
- scotty79 12y agoBasically it means that I think that hierarchical trust doesn't work for me. Instead of bank buying certificate from some authority I'm supposed to trust I'd rather infer that this certificate is associated with this domain because it's written in some form of blockchain, unalterable and verified by multiple parties. Honestly I have no idea how the current system is purported to work. And I just don't know what certificate is supposed to prove? That someone at some point in time had 100$ to spend on a cert? How's that more secure than self signed cert? Why browser warns about self-signed and not about others? All thing seems to me to be more of a security theatre and money making scheme than actual trust system that reflects reality in any way.
- cbr 12y ago> I just don't know what certificate is supposed to prove? That someone at some point in time had 100$ to spend on a cert? How's that more secure than self signed cert? A standard domain-validated cert proves that the CA saw you as in control of the site's DNS. Because spoofing DNS for client machines is generally much easier than for servers this is a big improvement in security over a self-signed cert.
- Xylakant 12y agobecause web-of-trust-models worked so great for PGP/GPG. In theory that's great, but how can I confirm that the cert in the chain is indeed for google.com. Because it's trusted by chrome which I downloaded from google.com (or at least a machine pretending to be google.com) or because my computer-illiterate friends trust it? Or because my OS trusts that cert? I agree that the current system is broken, but I fail to see how a distributed system magically fixes this, most notably the issue of bootstrapping trust. I foresee that the distributed model moves to a more centralized model where we trust apple, microsoft, ubuntu.
- giovani 12y agoI agree, the bootstrapping trust is a hard issue, and I don't think either that a distributed system will magically fix things. What would happen is we'd just change one set of problems for another one, but IMHO it'd be a better system overall. In this case, making things more visible is a better thing. That's an interesting point about the way a distributed model would evolve. My question is: does it matter? If we could more easily spot a bad actor, wouldn't it make everyone behave better?
- higherpurpose 12y agoProbably something like this: https://github.com/okTurtles/dnschain https://github.com/okTurtles/dnschain