{"type":"rich","version":"1.0","author_name":"npub1dtr22xd42nv07un2xq0rmtkqkjylgsmexau0anxxafa9xmmn2ncshu7wrs","author_url":"https://nostr.ae/npub1dtr22xd42nv07un2xq0rmtkqkjylgsmexau0anxxafa9xmmn2ncshu7wrs","provider_name":"njump","provider_url":"https://nostr.ae","html":"📅 Original date posted:2012-11-26\n📝 Original message:On Tuesday, November 27, 2012 12:16:07 AM Gregory Maxwell wrote:\n\u003e On Mon, Nov 26, 2012 at 6:44 PM, Luke-Jr \u003cluke at dashjr.org\u003e wrote:\n\u003e \u003e On Monday, November 26, 2012 11:32:46 PM Gregory Maxwell wrote:\n\u003e \u003e\u003e Would you find it acceptable if something supported a static whitelist\n\u003e \u003e\u003e plus a OS provided list minus a user configured blacklist and the\n\u003e \u003e\u003e ability for sophisticated users to disable the whitelist?\n\u003e \u003e \n\u003e \u003e How is this whitelist any different from the list of CAs included by\n\u003e \u003e default with every OS?\n\u003e \n\u003e Because the list is not identical (and of course, couldn't be without\n\u003e centralizing control of all OSes :P ) meaning that the software has to\n\u003e be setup in a way where false-positive authentication failures are a\n\u003e common thing (terrible for user security) or merchants have to waste a\n\u003e bunch of time, probably unsuccessfully, figuring out what certs work\n\u003e sufficiently 'everwhere' and likely end up handing over extortion\n\u003e level fees to the most well established CAs that happen to be included\n\u003e on the oldest and most obscure things.\n\nThere is a common subset of CAs which are included in all OSs.\nThat's the \"whitelist equivalent\". We or someone else could even setup a list \nof these common CAs for merchants if that is needed.\n\nThe fees CAs charge for certs is a flaw in the CA model in general, I don't \nsee that it's important for us to solve it."}
