<oembed><type>rich</type><version>1.0</version><author_name>npub12rkw0jajmsck4uwdtksdvtswrlkypusfryjzera7m4fhqta6jhdsz3aqxc</author_name><author_url>https://nostr.ae/npub12rkw0jajmsck4uwdtksdvtswrlkypusfryjzera7m4fhqta6jhdsz3aqxc</author_url><provider_name>njump</provider_name><provider_url>https://nostr.ae</provider_url><html>📅 Original date posted:2013-12-08&#xA;📝 Original message:On 8 December 2013 19:25, Gregory Maxwell &lt;gmaxwell at gmail.com&gt; wrote:&#xA;&#xA;&gt; On Sun, Dec 8, 2013 at 11:16 AM, Drak &lt;drak at zikula.org&gt; wrote:&#xA;&gt; &gt; BGP redirection is a reality and can be exploited without much&#xA;&gt;&#xA;&gt; You&#39;re managing to argue against SSL. Because it actually provides&#xA;&gt; basically protection against an attacker who can actively intercept&#xA;&gt; traffic to the server. Against that threat model SSL is clearly— based&#xA;&gt; on your comments— providing a false sense of security.&#xA;&#xA;&#xA;Let me clarify. SSL renders BGP redirection useless because the browser&#xA;holds the signatures of CA&#39;s it trusts: an attacker cannot spoof a&#xA;certificate because it needs to be signed by a trusted CA: that&#39;s the point&#xA;of SSL, it encrypts and proves identity, the latter part is what thwarts&#xA;MITM. If there was an MITM the browser screams pretty loudly about it with&#xA;a big threat warning interstitial.&#xA;&#xA;Regards,&#xA;&#xA;Drak&#xA;-------------- next part --------------&#xA;An HTML attachment was scrubbed...&#xA;URL: &lt;http://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20131208/9e49620a/attachment.html&gt;</html></oembed>