Re: Rant on HTTPS everywhere

Tony Arcieri <[email protected]>
Newsgroups gmane.comp.capabilities.general
Message-ID <CAHOTMVL2BNoNXAMzDVfa=m+Jn-HG2iejh7Pcmf-eOidojBvPvQ@mail.gmail.com>
On Thu, Jan 8, 2015 at 1:04 AM, Rob Meijer <rmeijer-qWit8jRvyhVmR6Xm/[email protected]> wrote:

> I think some on this list might find my rant on the HTTPS Everywhere thing
> an interesting read:
>

tl;dr: "Honest Achmed"?

I'm pretty sure many of you won't agree with my conclusions here. I've had
> discussions on this subject enough to know many people will agree with the
> validity of my arguments yet very few are ready to agree with the IMHO
> inevitable conclusions we should draw from those arguments.


DNSSEC "sounds" like the right conclusion, but given the extreme
complexity, poor design, lack of privacy/confidentiality, and
susceptibility to amplification attacks, is it?

What about fixes for the X.509 PKI like:

1) Public Key Pinning / HPKP
2) Name Constraints
3) Certificate Transparency

?

-- 
Tony Arcieri

_______________________________________________
cap-talk mailing list
[email protected]
http://www.eros-os.org/mailman/listinfo/cap-talk
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.