BLU Discuss list archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Discuss] root CA bloat
- Subject: [Discuss] root CA bloat
- From: richard.pieri at gmail.com (Richard Pieri)
- Date: Mon, 24 Nov 2014 21:35:16 -0500
- In-reply-to: <20141124202035.GI11734@dragontoe.org>
- References: <546C4823.6060900@gmail.com> <BN3PR0401MB1204BAB10AE6249C54E4E81BDC760@BN3PR0401MB1204.namprd04.prod.outlook.com> <546D7B55.70903@gmail.com> <BN3PR0401MB1204E9F1CF304F6724855281DC760@BN3PR0401MB1204.namprd04.prod.outlook.com> <546FC87F.1090203@gmail.com> <BN3PR0401MB120420D9FF67828E9C5551C4DC750@BN3PR0401MB1204.namprd04.prod.outlook.com> <54727CF6.9000301@gmail.com> <54728AD7.6040507@gmail.com> <20141124202035.GI11734@dragontoe.org>
On 11/24/2014 3:20 PM, Derek Martin wrote: > It is a practical impossibility for you (or your organization) to > actually truly authenticate each and every entity with whom you do > business on the Internet. The problem is compounded by the needs of I don't agree with the base assertion. I don't believe that it is an impossibility, practical or otherwise. Means to do it exist. Kerberos does it on a small scale. Make something like Kerberos realms integral to web browsers. Make doing business with Amazon a matter of creating a principal for Amazon in your browser profile. There you have it: verifiable, mutual authentication across the entire Internet. No, that's not intended to be the solution. It's me noodling about one way to go about it. Yes, I'm aware that this does not solve the initial trust problem. Like I wrote above, I don't believe it is impossible to solve, only that nobody has put the effort into solving it (or if they have then their work has largely been ignored). It wouldn't require a flag day. It's something that browser makers could implement and deploy in parallel with the existing X.509 PKI currently in use. X.509 could then be deprecated once the new system achieves a critical mass. -- Rich P.
- Follow-Ups:
- [Discuss] root CA bloat
- From: invalid at pizzashack.org (Derek Martin)
- [Discuss] root CA bloat
- References:
- [Discuss] free SSL certs from the EFF
- From: tmetro+blu at gmail.com (Tom Metro)
- [Discuss] free SSL certs from the EFF
- From: blu at nedharvey.com (Edward Ned Harvey (blu))
- [Discuss] free SSL certs from the EFF
- From: tmetro+blu at gmail.com (Tom Metro)
- [Discuss] free SSL certs from the EFF
- From: blu at nedharvey.com (Edward Ned Harvey (blu))
- [Discuss] root CA bloat
- From: tmetro+blu at gmail.com (Tom Metro)
- [Discuss] root CA bloat
- From: blu at nedharvey.com (Edward Ned Harvey (blu))
- [Discuss] root CA bloat
- From: tmetro+blu at gmail.com (Tom Metro)
- [Discuss] root CA bloat
- From: richard.pieri at gmail.com (Richard Pieri)
- [Discuss] root CA bloat
- From: invalid at pizzashack.org (Derek Martin)
- [Discuss] free SSL certs from the EFF
- Prev by Date: [Discuss] root CA bloat
- Next by Date: [Discuss] free SSL certs from the EFF
- Previous by thread: [Discuss] root CA bloat
- Next by thread: [Discuss] root CA bloat
- Index(es):