Re: don't follow the https'ers off the cliff... ;-)
L A Walsh <[email protected]> Mon, 19 Dec 2016 12:38:48 -0800
| Newsgroups | gmane.linux.suse.security |
|---|---|
| Message-ID | <[email protected]> |
Jean-Christophe Baptiste wrote: > I know that but as you say yourself, they serve two complementary purposes. I want HTTPS to download the media, otherwise the whole signature infrastructure is useless if I get a different operating system. --- If you get a different OS? how's that? > > I have worked for ISP and never heard of such a practice. So I may still be naive despite being paranoid by profession. ---- First widely known instance: https://freedom-to-tinker.com/2013/01/03/turktrust-certificate-authority-errors-demonstrate-the-risk-of-subordinate-certificates/ Mozilla acknowledging and stomping feet: http://www.computerworld.com/article/2495053/desktop-apps/mozilla-moves-to-limit-risk-of-subordinate-ca-certificate-abuse.html It's happened, it's acknowledged, Mozilla threatens actions, but can only ask for administrative controls. -- To unsubscribe, e-mail: [email protected] To contact the owner, e-mail: [email protected]