Re: Google warns of unauthorized TLS certificates trusted by almost all OSes
Marc Fawzi <[email protected]>
| Newsgroups | gmane.org.w3c.tag |
|---|---|
| Message-ID | <CACioZituT9C0HGzuzfO4yDpmjo6aBGO9mM1jVb2_FXX73Xsv=A@mail.gmail.com> |
<<Defenders of the current system for acquiring and revoking TLS certificates have recently chafed in response to statements from this author <https://twitter.com/ivanristic/status/578536108662861824> that it's *hopelessly broken*. Besides remembering that almost all of these critics have a strong financial interest in the way the system works now >> What prevents a state spy agency from MITM-ing your HTTPS connection? Why don't you answer that? And why would you refer to the comment I made as "alarmist" (in dismissive tone, no less) given the situation is factually _alarming_? On Tue, Mar 24, 2015 at 12:42 PM, Daniel Appelquist <[email protected]> wrote: > Excuse me? > > Marc – can you please refrain from making alarmist, nonsensical > flame-baiting comments like this on our mailing list? Probably this sort of > thing would be more sensibly expressed on Twitter or similar? > > Thanks, > Dan > > On 24 Mar 2015, at 16:47, Marc Fawzi <[email protected]> wrote: > > A classic "we told you so" moment for "HTTPS everywhere" promoters and now > state surveillance is baked into HTTP2.0 > > Sent from my iPhone > > On Mar 24, 2015, at 9:31 AM, Melvin Carvalho <[email protected]> > wrote: > > FYI: > > > http://arstechnica.com/security/2015/03/google-warns-of-unauthorized-tls-certificates-trusted-by-almost-all-oses/ > > > >