{"type":"rich","version":"1.0","author_name":"npub1f2nvlx49er5c7sqa43src6ssyp6snd4qwvtkwm5avc2l84cs84esecrwet","author_url":"https://nostr.ae/npub1f2nvlx49er5c7sqa43src6ssyp6snd4qwvtkwm5avc2l84cs84esecrwet","provider_name":"njump","provider_url":"https://nostr.ae","html":"📅 Original date posted:2012-11-26\n📝 Original message:On Mon, Nov 26, 2012 at 6:19 PM, Luke-Jr \u003cluke at dashjr.org\u003e wrote:\n\u003e On Monday, November 26, 2012 11:16:03 PM Mike Hearn wrote:\n\u003e\u003e They could be included as well of course, but from a seller\n\u003e\u003e perspective the most important thing is consistency. You have to be\n\u003e\u003e able to predict what CAs the user has, otherwise your invoice would\n\u003e\u003e appear in the UI as unverified and is subject to manipulation by\n\u003e\u003e viruses, etc.\n\u003e\n\u003e That's expected behaviour - except it's mainly be manipulated by *users*, not\n\u003e viruses (which can just as easily manipulate whatever custom cert store we\n\u003e use). If I don't trust Joe's certs, I don't want Bitcoin overriding that no\n\u003e matter who Joe is or what connections he has.\n\u003e\n\u003e\u003e So using the OS cert store would effectively restrict merchants to the\n\u003e\u003e intersection of what ships in all the operating systems their users\n\u003e\u003e use, which could be unnecessarily restrictive. As far as I know, every\n\u003e\u003e browser has its own cert store for that reason.\n\u003e\n\u003e Browsers with this bug are not relevant IMO.\n\n\nThis is messy.   It's important to people to know that their cert will\nbe accepted by ~everyone because non-acceptance looks like malice.  If\nthe cert system is actually to provide value then false positives need\nto be low enough that people can start calling in law enforcement,\ncomputer investigators, etc.. every time a cert failure happens.\nOtherwise there is little incentive for an attacker to not _try_.\n\nObviously the state of the world with browsers is not that good... but\nin our own UAs we can do better and get closer to that.\n\nWould you find it acceptable if something supported a static whitelist\nplus a OS provided list minus a user configured blacklist and the\nability for sophisticated users to disable the whitelist?\n\nThis way people could trust that if their cert is signed via one on\nthe whitelist they'll work for ALL normal users.. and the UI can have\nvery strong behavior that protects people (e.g. no 'click here to\ndisable all security because tldr' button)... but advanced users who\ncan deal with sorting out failure can still have complete control\nincluding OS based control."}
