<oembed><type>rich</type><version>1.0</version><author_name>npub12rkw0jajmsck4uwdtksdvtswrlkypusfryjzera7m4fhqta6jhdsz3aqxc</author_name><author_url>https://nostr.ae/npub12rkw0jajmsck4uwdtksdvtswrlkypusfryjzera7m4fhqta6jhdsz3aqxc</author_url><provider_name>njump</provider_name><provider_url>https://nostr.ae</provider_url><html>📅 Original date posted:2013-12-08&#xA;📝 Original message:On 8 December 2013 12:37, Luke-Jr &lt;luke at dashjr.org&gt; wrote:&#xA;&#xA;&gt; Encryption is useless here. We want everyone to be able to download Bitcoin&#xA;&gt; clients. Binaries on sourceforge are signed by multiple parties using&#xA;&gt; gitian.&#xA;&gt;&#xA;&gt; &gt; Decentralization:&#xA;&gt; &gt; So long as we actually use DNS, the website is centralized :( However,&#xA;&gt; &gt; its content isn&#39;t (can be forked on GitHub), but regarding the domain&#xA;&gt; &gt; name, there is not much we can do against this AFAIK.&#xA;&gt;&#xA;&gt; So long as someone has root (or a user that can modify it), the website is&#xA;&gt; centralised. To really solve this, we would need a dedicated server that&#xA;&gt; accepts commands only when signed by N-of-M parties, inside a cage locked&#xA;&gt; by&#xA;&gt; padlocks with keys held by independent parties, with a SSL certificate&#xA;&gt; issued&#xA;&gt; by an authority that has multiple parties watch it every step of the way&#xA;&gt; into&#xA;&gt; that server.&#xA;&#xA;&#xA;Malicious actors with root access to the server is another issue entirely.&#xA;Sure it&#39;s a problem, but it is not an argument not to have a properly&#xA;signed SSL certificate.&#xA;&#xA;With out one, the exploit can be performed on routers to redirect traffic&#xA;through a third party alter the content of the site (like the links on&#xA;bitcoin.org to various wallet projects) and then onto the correct&#xA;destination. SSL at least mitigates that. For example it would be trivial&#xA;to impersonate Electrum&#39;s site or whatever, &#34;change&#34; the link on the fly&#xA;that appears on the trusted source bitcoin.org via BGP redirection. Now&#xA;users will be directed to the scammers site which could be identical except&#xA;for domain name and of course malicious binaries.&#xA;&#xA;BGP redirection is a reality and can be exploited without much&#xA;expense/effort. MITM is a real world threat, not some theoretical&#xA;possibility - reports show it&#39;s happening on an unprecedented scale. SSL is&#xA;essential - that&#39;s a no-brainer. Sure other measures are important, but&#xA;without SSL there is almost no point to any of the other options.&#xA;&#xA;SSL is so considered so important that the *HTTP 2.0 spec might be SSL&#xA;only*according to recent discussions at the W3C (&#xA;http://lists.w3.org/Archives/Public/ietf-http-wg/2013OctDec/0625.html).&#xA;&#xA;Drak&#xA;-------------- next part --------------&#xA;An HTML attachment was scrubbed...&#xA;URL: &lt;http://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20131208/c6778642/attachment.html&gt;</html></oembed>