<oembed><type>rich</type><version>1.0</version><author_name>npub1f2nvlx49er5c7sqa43src6ssyp6snd4qwvtkwm5avc2l84cs84esecrwet</author_name><author_url>https://nostr.ae/npub1f2nvlx49er5c7sqa43src6ssyp6snd4qwvtkwm5avc2l84cs84esecrwet</author_url><provider_name>njump</provider_name><provider_url>https://nostr.ae</provider_url><html>📅 Original date posted:2012-11-26&#xA;📝 Original message:On Mon, Nov 26, 2012 at 6:19 PM, Luke-Jr &lt;luke at dashjr.org&gt; wrote:&#xA;&gt; On Monday, November 26, 2012 11:16:03 PM Mike Hearn wrote:&#xA;&gt;&gt; They could be included as well of course, but from a seller&#xA;&gt;&gt; perspective the most important thing is consistency. You have to be&#xA;&gt;&gt; able to predict what CAs the user has, otherwise your invoice would&#xA;&gt;&gt; appear in the UI as unverified and is subject to manipulation by&#xA;&gt;&gt; viruses, etc.&#xA;&gt;&#xA;&gt; That&#39;s expected behaviour - except it&#39;s mainly be manipulated by *users*, not&#xA;&gt; viruses (which can just as easily manipulate whatever custom cert store we&#xA;&gt; use). If I don&#39;t trust Joe&#39;s certs, I don&#39;t want Bitcoin overriding that no&#xA;&gt; matter who Joe is or what connections he has.&#xA;&gt;&#xA;&gt;&gt; So using the OS cert store would effectively restrict merchants to the&#xA;&gt;&gt; intersection of what ships in all the operating systems their users&#xA;&gt;&gt; use, which could be unnecessarily restrictive. As far as I know, every&#xA;&gt;&gt; browser has its own cert store for that reason.&#xA;&gt;&#xA;&gt; Browsers with this bug are not relevant IMO.&#xA;&#xA;&#xA;This is messy.   It&#39;s important to people to know that their cert will&#xA;be accepted by ~everyone because non-acceptance looks like malice.  If&#xA;the cert system is actually to provide value then false positives need&#xA;to be low enough that people can start calling in law enforcement,&#xA;computer investigators, etc.. every time a cert failure happens.&#xA;Otherwise there is little incentive for an attacker to not _try_.&#xA;&#xA;Obviously the state of the world with browsers is not that good... but&#xA;in our own UAs we can do better and get closer to that.&#xA;&#xA;Would you find it acceptable if something supported a static whitelist&#xA;plus a OS provided list minus a user configured blacklist and the&#xA;ability for sophisticated users to disable the whitelist?&#xA;&#xA;This way people could trust that if their cert is signed via one on&#xA;the whitelist they&#39;ll work for ALL normal users.. and the UI can have&#xA;very strong behavior that protects people (e.g. no &#39;click here to&#xA;disable all security because tldr&#39; button)... but advanced users who&#xA;can deal with sorting out failure can still have complete control&#xA;including OS based control.</html></oembed>