{"type":"rich","version":"1.0","author_name":"npub12rkw0jajmsck4uwdtksdvtswrlkypusfryjzera7m4fhqta6jhdsz3aqxc","author_url":"https://nostr.ae/npub12rkw0jajmsck4uwdtksdvtswrlkypusfryjzera7m4fhqta6jhdsz3aqxc","provider_name":"njump","provider_url":"https://nostr.ae","html":"📅 Original date posted:2013-12-08\n📝 Original message:On 8 December 2013 19:25, Gregory Maxwell \u003cgmaxwell at gmail.com\u003e wrote:\n\n\u003e On Sun, Dec 8, 2013 at 11:16 AM, Drak \u003cdrak at zikula.org\u003e wrote:\n\u003e \u003e BGP redirection is a reality and can be exploited without much\n\u003e\n\u003e You're managing to argue against SSL. Because it actually provides\n\u003e basically protection against an attacker who can actively intercept\n\u003e traffic to the server. Against that threat model SSL is clearly— based\n\u003e on your comments— providing a false sense of security.\n\n\nLet me clarify. SSL renders BGP redirection useless because the browser\nholds the signatures of CA's it trusts: an attacker cannot spoof a\ncertificate because it needs to be signed by a trusted CA: that's the point\nof SSL, it encrypts and proves identity, the latter part is what thwarts\nMITM. If there was an MITM the browser screams pretty loudly about it with\na big threat warning interstitial.\n\nRegards,\n\nDrak\n-------------- next part --------------\nAn HTML attachment was scrubbed...\nURL: \u003chttp://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20131208/9e49620a/attachment.html\u003e"}
