{"type":"rich","version":"1.0","author_name":"npub1nxlvf9mj3jzgue25n5d9y47s3h5hvg0ded9hwpejdxj9mtrs34vs97wjrv","author_url":"https://nostr.ae/npub1nxlvf9mj3jzgue25n5d9y47s3h5hvg0ded9hwpejdxj9mtrs34vs97wjrv","provider_name":"njump","provider_url":"https://nostr.ae","html":"📅 Original date posted:2011-12-19\n🗒️ Summary of this message: HTTPS issues are social, not technical, with multiple CAs being tricked or strong-armed into issuing fake certificates. Bitcoin cannot solve this problem.\n📝 Original message:On 2011 December 19 Monday, Jorge Timón wrote:\n\u003e Ok, so HTTP is not an option unless it shows a huge warning. I don't\n\u003e know the HTTPS possible attack, but maybe it needs a warning message\n\u003e too, from what you people are saying. Although using namecoin to\n\nThe problems with HTTPS have been social rather than technical.  Multiple CAs \nhave been strong-armed by governments or tricked into issuing fake \ncertificates by scammers.  There is no technical measure around that.  By \nusing the CA certificate we are saying to the system \"here is someone I trust \nto issue a certificate\".  So far, with a large number of CAs, that trust is \nmisplaced.\n\nI'm of the opinion though that this problem is outside the remit of bitcoin to \nsolve.\n\nPerhaps we should be more strict about which CA certificates are trusted by \nthe bitcoin client: say restrict it to those who have demonstrably good \npractices for verifying identity; rather than the ridiculous amount of trust \nthat comes pre-installed for me in my browser.\n\n\n\nAndy\n\n-- \nDr Andy Parkins\nandyparkins at gmail.com\n-------------- next part --------------\nA non-text attachment was scrubbed...\nName: signature.asc\nType: application/pgp-signature\nSize: 198 bytes\nDesc: This is a digitally signed message part.\nURL: \u003chttp://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20111219/b557a325/attachment.sig\u003e"}
