disabling HSTS
disabling HSTS
Posted Apr 18, 2017 13:22 UTC (Tue) by bandrami (guest, #94229)In reply to: disabling HSTS by tialaramex
Parent article: Tor exit node operator arrested in Russia (TorServers.net blog)
Seriously, this seems so obvious: there are two questions that TLS is trying to answer at once. I want to know
A) is the transport between me and the other party secure? and sometimes
B) is the other party who he or she claims to be?
For most traffic (where even a verified A isn't particularly trusted), A is the much more important question, and hand-wringing about B has prevented widespread adoption of simple techniques to solve A. Establish a secure channel, and we can then use that to negotiate authenticity.
