{"type":"rich","version":"1.0","author_name":"npub1f2nvlx49er5c7sqa43src6ssyp6snd4qwvtkwm5avc2l84cs84esecrwet","author_url":"https://nostr.ae/npub1f2nvlx49er5c7sqa43src6ssyp6snd4qwvtkwm5avc2l84cs84esecrwet","provider_name":"njump","provider_url":"https://nostr.ae","html":"📅 Original date posted:2012-11-26\n📝 Original message:On Mon, Nov 26, 2012 at 6:44 PM, Luke-Jr \u003cluke at dashjr.org\u003e wrote:\n\u003e On Monday, November 26, 2012 11:32:46 PM Gregory Maxwell wrote:\n\u003e\u003e Obviously the state of the world with browsers is not that good... but\n\u003e\u003e in our own UAs we can do better and get closer to that.\n\u003e\n\u003e This effectively centralizes Bitcoin (at least in the eyes of many) and even\n\u003e if each competing client had their own list, you'd be back to the original\n\u003e \"problem\" of not being sure your CA is on all lists.\n\nThats the CA model generally. It _is_ a distributed-centralized model\nin practice.\n\n\u003e\u003e Would you find it acceptable if something supported a static whitelist\n\u003e\u003e plus a OS provided list minus a user configured blacklist and the\n\u003e\u003e ability for sophisticated users to disable the whitelist?\n\u003e\n\u003e How is this whitelist any different from the list of CAs included by default\n\u003e with every OS?\n\nBecause the list is not identical (and of course, couldn't be without\ncentralizing control of all OSes :P ) meaning that the software has to\nbe setup in a way where false-positive authentication failures are a\ncommon thing (terrible for user security) or merchants have to waste a\nbunch of time, probably unsuccessfully, figuring out what certs work\nsufficiently 'everwhere' and likely end up handing over extortion\nlevel fees to the most well established CAs that happen to be included\non the oldest and most obscure things.\n\nTaking— say— the intersection of Chrome, Webkit, and Firefox's CA list\nas of the first of the year every year and putting the result on a\nwhitelist would be a possible nothing-up-my-sleeve approach which is\nnot as limited as having some users subject to the WinXP cert list,\nwhich IIRC is very limited (but not in a way that improves security!).\n\nJeff wrote:\n\u003e Self-signed certs are quite common, because it is easier, while being\n\u003e more secure than http://\n\nUhh.  Really?   Well, I agree with you that they should be (I\nunsuccessfully lobbied browser vendors to make self-signed https on\nhttp URLs JustWork and simply hide all user visible evidence of\nsecurity), but the really nasty warnings on those sites undermines the\nsecurity of the sites _and_ of other HTTPS sites because it conditions\nusers to click ignore-ignore-ignore. I don't think they are all that\ncommon.\n\nOne thing which I think will be hard for us in this discussion is\nbeing sensitive to the (quite justified!) concerns that the current CA\nsystem is absolute rubbish, both terrible for security, usability, and\nan unreasonable barrier to entry relative to the provided security—\nwithout allowing the discussion to be usurped by everyone's pet\nreplacement, which there are a great many of with varying feasibility\nand security.\n\nPerhaps we should agree to talk about everything _except_ that first?"}
