<oembed><type>rich</type><version>1.0</version><author_name>npub1dtr22xd42nv07un2xq0rmtkqkjylgsmexau0anxxafa9xmmn2ncshu7wrs</author_name><author_url>https://nostr.ae/npub1dtr22xd42nv07un2xq0rmtkqkjylgsmexau0anxxafa9xmmn2ncshu7wrs</author_url><provider_name>njump</provider_name><provider_url>https://nostr.ae</provider_url><html>📅 Original date posted:2012-11-26&#xA;📝 Original message:On Tuesday, November 27, 2012 12:16:07 AM Gregory Maxwell wrote:&#xA;&gt; On Mon, Nov 26, 2012 at 6:44 PM, Luke-Jr &lt;luke at dashjr.org&gt; wrote:&#xA;&gt; &gt; On Monday, November 26, 2012 11:32:46 PM Gregory Maxwell wrote:&#xA;&gt; &gt;&gt; Would you find it acceptable if something supported a static whitelist&#xA;&gt; &gt;&gt; plus a OS provided list minus a user configured blacklist and the&#xA;&gt; &gt;&gt; ability for sophisticated users to disable the whitelist?&#xA;&gt; &gt; &#xA;&gt; &gt; How is this whitelist any different from the list of CAs included by&#xA;&gt; &gt; default with every OS?&#xA;&gt; &#xA;&gt; Because the list is not identical (and of course, couldn&#39;t be without&#xA;&gt; centralizing control of all OSes :P ) meaning that the software has to&#xA;&gt; be setup in a way where false-positive authentication failures are a&#xA;&gt; common thing (terrible for user security) or merchants have to waste a&#xA;&gt; bunch of time, probably unsuccessfully, figuring out what certs work&#xA;&gt; sufficiently &#39;everwhere&#39; and likely end up handing over extortion&#xA;&gt; level fees to the most well established CAs that happen to be included&#xA;&gt; on the oldest and most obscure things.&#xA;&#xA;There is a common subset of CAs which are included in all OSs.&#xA;That&#39;s the &#34;whitelist equivalent&#34;. We or someone else could even setup a list &#xA;of these common CAs for merchants if that is needed.&#xA;&#xA;The fees CAs charge for certs is a flaw in the CA model in general, I don&#39;t &#xA;see that it&#39;s important for us to solve it.</html></oembed>