<oembed><type>rich</type><version>1.0</version><author_name>npub1f2nvlx49er5c7sqa43src6ssyp6snd4qwvtkwm5avc2l84cs84esecrwet</author_name><author_url>https://nostr.ae/npub1f2nvlx49er5c7sqa43src6ssyp6snd4qwvtkwm5avc2l84cs84esecrwet</author_url><provider_name>njump</provider_name><provider_url>https://nostr.ae</provider_url><html>📅 Original date posted:2012-11-26&#xA;📝 Original message:On Mon, Nov 26, 2012 at 6:44 PM, Luke-Jr &lt;luke at dashjr.org&gt; wrote:&#xA;&gt; On Monday, November 26, 2012 11:32:46 PM Gregory Maxwell wrote:&#xA;&gt;&gt; Obviously the state of the world with browsers is not that good... but&#xA;&gt;&gt; in our own UAs we can do better and get closer to that.&#xA;&gt;&#xA;&gt; This effectively centralizes Bitcoin (at least in the eyes of many) and even&#xA;&gt; if each competing client had their own list, you&#39;d be back to the original&#xA;&gt; &#34;problem&#34; of not being sure your CA is on all lists.&#xA;&#xA;Thats the CA model generally. It _is_ a distributed-centralized model&#xA;in practice.&#xA;&#xA;&gt;&gt; Would you find it acceptable if something supported a static whitelist&#xA;&gt;&gt; plus a OS provided list minus a user configured blacklist and the&#xA;&gt;&gt; ability for sophisticated users to disable the whitelist?&#xA;&gt;&#xA;&gt; How is this whitelist any different from the list of CAs included by default&#xA;&gt; with every OS?&#xA;&#xA;Because the list is not identical (and of course, couldn&#39;t be without&#xA;centralizing control of all OSes :P ) meaning that the software has to&#xA;be setup in a way where false-positive authentication failures are a&#xA;common thing (terrible for user security) or merchants have to waste a&#xA;bunch of time, probably unsuccessfully, figuring out what certs work&#xA;sufficiently &#39;everwhere&#39; and likely end up handing over extortion&#xA;level fees to the most well established CAs that happen to be included&#xA;on the oldest and most obscure things.&#xA;&#xA;Taking— say— the intersection of Chrome, Webkit, and Firefox&#39;s CA list&#xA;as of the first of the year every year and putting the result on a&#xA;whitelist would be a possible nothing-up-my-sleeve approach which is&#xA;not as limited as having some users subject to the WinXP cert list,&#xA;which IIRC is very limited (but not in a way that improves security!).&#xA;&#xA;Jeff wrote:&#xA;&gt; Self-signed certs are quite common, because it is easier, while being&#xA;&gt; more secure than http://&#xA;&#xA;Uhh.  Really?   Well, I agree with you that they should be (I&#xA;unsuccessfully lobbied browser vendors to make self-signed https on&#xA;http URLs JustWork and simply hide all user visible evidence of&#xA;security), but the really nasty warnings on those sites undermines the&#xA;security of the sites _and_ of other HTTPS sites because it conditions&#xA;users to click ignore-ignore-ignore. I don&#39;t think they are all that&#xA;common.&#xA;&#xA;One thing which I think will be hard for us in this discussion is&#xA;being sensitive to the (quite justified!) concerns that the current CA&#xA;system is absolute rubbish, both terrible for security, usability, and&#xA;an unreasonable barrier to entry relative to the provided security—&#xA;without allowing the discussion to be usurped by everyone&#39;s pet&#xA;replacement, which there are a great many of with varying feasibility&#xA;and security.&#xA;&#xA;Perhaps we should agree to talk about everything _except_ that first?</html></oembed>