<oembed><type>rich</type><version>1.0</version><author_name>npub1nxlvf9mj3jzgue25n5d9y47s3h5hvg0ded9hwpejdxj9mtrs34vs97wjrv</author_name><author_url>https://nostr.ae/npub1nxlvf9mj3jzgue25n5d9y47s3h5hvg0ded9hwpejdxj9mtrs34vs97wjrv</author_url><provider_name>njump</provider_name><provider_url>https://nostr.ae</provider_url><html>📅 Original date posted:2011-12-19&#xA;🗒️ Summary of this message: HTTPS issues are social, not technical, with multiple CAs being tricked or strong-armed into issuing fake certificates. Bitcoin cannot solve this problem.&#xA;📝 Original message:On 2011 December 19 Monday, Jorge Timón wrote:&#xA;&gt; Ok, so HTTP is not an option unless it shows a huge warning. I don&#39;t&#xA;&gt; know the HTTPS possible attack, but maybe it needs a warning message&#xA;&gt; too, from what you people are saying. Although using namecoin to&#xA;&#xA;The problems with HTTPS have been social rather than technical.  Multiple CAs &#xA;have been strong-armed by governments or tricked into issuing fake &#xA;certificates by scammers.  There is no technical measure around that.  By &#xA;using the CA certificate we are saying to the system &#34;here is someone I trust &#xA;to issue a certificate&#34;.  So far, with a large number of CAs, that trust is &#xA;misplaced.&#xA;&#xA;I&#39;m of the opinion though that this problem is outside the remit of bitcoin to &#xA;solve.&#xA;&#xA;Perhaps we should be more strict about which CA certificates are trusted by &#xA;the bitcoin client: say restrict it to those who have demonstrably good &#xA;practices for verifying identity; rather than the ridiculous amount of trust &#xA;that comes pre-installed for me in my browser.&#xA;&#xA;&#xA;&#xA;Andy&#xA;&#xA;-- &#xA;Dr Andy Parkins&#xA;andyparkins at gmail.com&#xA;-------------- next part --------------&#xA;A non-text attachment was scrubbed...&#xA;Name: signature.asc&#xA;Type: application/pgp-signature&#xA;Size: 198 bytes&#xA;Desc: This is a digitally signed message part.&#xA;URL: &lt;http://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20111219/b557a325/attachment.sig&gt;</html></oembed>