BLU Discuss list archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Discuss] free SSL certs from the EFF
- Subject: [Discuss] free SSL certs from the EFF
- From: me at mattgillen.net (Matthew Gillen)
- Date: Fri, 05 Dec 2014 09:43:20 -0500
- In-reply-to: <CA+h9Qs5wWchqNJxCWQ4ty7RaFSd+JtfFS6hVQQF19-0O2ZnqDQ@mail.gmail.com>
- References: <sjm8uirdxem.fsf@securerf.ihtfp.org> <BN3PR0401MB1204B299B351DFF7F2E85FBDDC7D0@BN3PR0401MB1204.namprd04.prod.outlook.com> <sjmlhmqcb1j.fsf@securerf.ihtfp.org> <BN3PR0401MB120492A5BDE4D3CEE0AECDD3DC7A0@BN3PR0401MB1204.namprd04.prod.outlook.com> <sjm8uiqc7sw.fsf@securerf.ihtfp.org> <547E0FB3.3070005@gmail.com> <sjmy4qobui6.fsf@securerf.ihtfp.org> <547F3855.10106@gmail.com> <sjmtx1bbf7w.fsf@securerf.ihtfp.org> <5480856D.6050205@gmail.com> <20141204163645.GA11641@dragontoe.org> <54809327.5040802@gmail.com> <225b01d00fe5$dde00d40$99a027c0$@Polcari.com> <5480A14C.1080303@gmail.com> <CA+h9Qs5wWchqNJxCWQ4ty7RaFSd+JtfFS6hVQQF19-0O2ZnqDQ@mail.gmail.com>
On 12/04/2014 11:42 PM, John Abreau wrote: > On Thu, Dec 4, 2014 at 1:00 PM, Richard Pieri <richard.pieri at gmail.com> > wrote: > >> On 12/4/2014 12:15 PM, Joe Polcari wrote: >> >>> To me, that's a good reason for things to stop working. >>> >> >> For certain values of "good" I suppose. >> >> Good news: your email wasn't hacked. >> Bad news: you're fired for failing to submit your reports on time. > > > On the other hand, if you accept the bad guy's poisoned DNS data: > > Good news: you feel secure because you sent out your reports on time. > Bad news: They were sent to the bad guy's mail server, so you're still > fired for failing to submit your reports on time to your employer's mail > server. Worse news: the DNS misdirection enabled a MITM attack that captured your credentials, and your credentials are used to hack into the company and cause a data breach. Then they have a real reason to fire you (has anyone actually been fired for not submitting reports on time?). I know the example wasn't meant to be taken literally, but the point is that typically it is far worse to allow your credentials to be compromised than it is to have delays in doing your job. Obviously the degree to which this is true varies from job to job, but the point remains that if you're ignoring authenticity with respect to what machines you are talking to, you can't be sure you are actually doing your job. So that is why DoS should always be the preferred failure mode when authenticity can't be verified. Matt
- References:
- [Discuss] free SSL certs from the EFF
- From: warlord at MIT.EDU (Derek Atkins)
- [Discuss] free SSL certs from the EFF
- From: blu at nedharvey.com (Edward Ned Harvey (blu))
- [Discuss] free SSL certs from the EFF
- From: warlord at MIT.EDU (Derek Atkins)
- [Discuss] free SSL certs from the EFF
- From: blu at nedharvey.com (Edward Ned Harvey (blu))
- [Discuss] free SSL certs from the EFF
- From: warlord at MIT.EDU (Derek Atkins)
- [Discuss] free SSL certs from the EFF
- From: richard.pieri at gmail.com (Richard Pieri)
- [Discuss] free SSL certs from the EFF
- From: warlord at MIT.EDU (Derek Atkins)
- [Discuss] free SSL certs from the EFF
- From: richard.pieri at gmail.com (Richard Pieri)
- [Discuss] free SSL certs from the EFF
- From: warlord at MIT.EDU (Derek Atkins)
- [Discuss] free SSL certs from the EFF
- From: richard.pieri at gmail.com (Richard Pieri)
- [Discuss] free SSL certs from the EFF
- From: invalid at pizzashack.org (Derek Martin)
- [Discuss] free SSL certs from the EFF
- From: richard.pieri at gmail.com (Richard Pieri)
- [Discuss] free SSL certs from the EFF
- From: Joe at Polcari.com (Joe Polcari)
- [Discuss] free SSL certs from the EFF
- From: richard.pieri at gmail.com (Richard Pieri)
- [Discuss] free SSL certs from the EFF
- From: jabr at blu.org (John Abreau)
- [Discuss] free SSL certs from the EFF
- Prev by Date: [Discuss] free SSL certs from the EFF
- Next by Date: [Discuss] free SSL certs from the EFF
- Previous by thread: [Discuss] free SSL certs from the EFF
- Next by thread: [Discuss] free SSL certs from the EFF
- Index(es):