Re: Google warns of unauthorized TLS certificates trusted by almost all OSes

Marc Fawzi <[email protected]>
Newsgroups gmane.org.w3c.tag
Message-ID <CACioZituT9C0HGzuzfO4yDpmjo6aBGO9mM1jVb2_FXX73Xsv=A@mail.gmail.com>
<<Defenders of the current system for acquiring and revoking TLS
certificates have recently chafed in response to statements from this author
<https://twitter.com/ivanristic/status/578536108662861824> that it's
*hopelessly
broken*. Besides remembering that almost all of these critics have a strong
financial interest in the way the system works now
>>

What prevents a state spy agency from MITM-ing your HTTPS connection? Why
don't you answer that?

And why would you refer to the comment I made as "alarmist" (in dismissive
tone, no less) given the situation is factually _alarming_?





On Tue, Mar 24, 2015 at 12:42 PM, Daniel Appelquist <[email protected]>
wrote:

> Excuse me?
>
> Marc – can you please refrain from making alarmist, nonsensical
> flame-baiting comments like this on our mailing list? Probably this sort of
> thing would be more sensibly expressed on Twitter or similar?
>
> Thanks,
> Dan
>
> On 24 Mar 2015, at 16:47, Marc Fawzi <[email protected]> wrote:
>
> A classic "we told you so" moment for "HTTPS everywhere" promoters and now
> state surveillance is baked into HTTP2.0
>
> Sent from my iPhone
>
> On Mar 24, 2015, at 9:31 AM, Melvin Carvalho <[email protected]>
> wrote:
>
> FYI:
>
>
> http://arstechnica.com/security/2015/03/google-warns-of-unauthorized-tls-certificates-trusted-by-almost-all-oses/
>
>
>
>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.