Re: Rant on HTTPS everywhere
Ben Laurie <[email protected]>
| Newsgroups | gmane.comp.capabilities.general |
|---|---|
| Message-ID | <CABrd9SR3p0RTYbG2mea5bbD39uVjnP3cJ7eFgYDuSxxfi4P=GA@mail.gmail.com> |
On 8 January 2015 at 09:04, Rob Meijer <rmeijer-qWit8jRvyhVmR6Xm/[email protected]> wrote: > I think some on this list might find my rant on the HTTPS Everywhere thing > an interesting read: > > http://minorfs.wordpress.com/2015/01/07/why-https-everywhere-is-a-horrible-idea-for-now/ > > I'm pretty sure many of you won't agree with my conclusions here. I've had > discussions on this subject enough to know many people will agree with the > validity of my arguments yet very few are ready to agree with the IMHO > inevitable conclusions we should draw from those arguments. Two things: 1. Certificate Transparency. Check it out. 2. DANE: guess what? Registries and registrars are no better than CAs. In fact, quite a lot worse. In short: I get the problem. I don't see easy answers.