Re: Rant on HTTPS everywhere
Tony Arcieri <[email protected]>
| Newsgroups | gmane.comp.capabilities.general |
|---|---|
| Message-ID | <CAHOTMVL2BNoNXAMzDVfa=m+Jn-HG2iejh7Pcmf-eOidojBvPvQ@mail.gmail.com> |
On Thu, Jan 8, 2015 at 1:04 AM, Rob Meijer <rmeijer-qWit8jRvyhVmR6Xm/[email protected]> wrote: > I think some on this list might find my rant on the HTTPS Everywhere thing > an interesting read: > tl;dr: "Honest Achmed"? I'm pretty sure many of you won't agree with my conclusions here. I've had > discussions on this subject enough to know many people will agree with the > validity of my arguments yet very few are ready to agree with the IMHO > inevitable conclusions we should draw from those arguments. DNSSEC "sounds" like the right conclusion, but given the extreme complexity, poor design, lack of privacy/confidentiality, and susceptibility to amplification attacks, is it? What about fixes for the X.509 PKI like: 1) Public Key Pinning / HPKP 2) Name Constraints 3) Certificate Transparency ? -- Tony Arcieri _______________________________________________ cap-talk mailing list [email protected] http://www.eros-os.org/mailman/listinfo/cap-talk