Convergence: User-controlled SSL certificate checking
Convergence: User-controlled SSL certificate checking
Posted Oct 28, 2011 9:21 UTC (Fri) by michi (guest, #60274)Parent article: Convergence: User-controlled SSL certificate checking
Posted Oct 28, 2011 18:29 UTC (Fri)
by sblack (guest, #81076)
[Link] (1 responses)
Posted Oct 29, 2011 14:37 UTC (Sat)
by michi (guest, #60274)
[Link]
I agree with you that shifting the trust to DNS providers will not really solve much. But my point was actually: If the dnssec cannot be trusted, why should perspectives be trusted?
However, I still think DNSSEC is good. First it can be implemented additional to CAs, so there are 2 layers of security. Second, only the dns provider can compromise a specific site and not a huge number of unrelated organisations.
The approach I like best is using .onion like addresses with the crypto key encoded in the url.
Convergence: User-controlled SSL certificate checking
Convergence: User-controlled SSL certificate checking