[foaf-dev] Webid and IS, private conversation partly forwarded

cr <[email protected]> Wed, 5 Mar 2014 22:42:10 +0000
Newsgroups gmane.comp.web.rdfweb
Message-ID <[email protected]>
> WIndows SSL comes with several architectural/assurance properties 

is the source of "WIndows SSL" (including all depended-upon libraries and OS kernels) open for inspection by security researchers? "assurance" meaning "because sales/marketing people say it's secure" (until the next hole is found and not reported because it's more profitable to sell baskets of holes on the spammer/botnet black-market than openly-disclose on security-MLs of via usually-paltry bounty-programs) ? more likely to occur outside the more-audited SSL library and in a UI library, rogue 3rdparty proprietary-blob plugin, IPC-silliness sandboxing-workaround loophole. i feel more secure with Nginx/Chromium than a system not open to inspection but otherwise implementing the same protocols

any reason a bunch of users w/ their own certificates is not closer to the PGP web-of-trust scenario than most developments on the web in the past 2 decades, primarily centered around capturing users into silos w/ no security at all