[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: ca-certificates: no more cacert.org certificates?!?



Marc Haber <mh+debian-devel@zugschlus.de> writes:

> On Mon, 31 Mar 2014 16:03:30 -0700, Russ Allbery <rra@debian.org>
> wrote:
>>Of course, I'm one of those people who believes that web site certificate
>>signatures as currently implemented, with the level of vetting that's
>>actually done by commercial CAs in practice, are more of an extortion
>>racket than a security measure.
>
> I have to agree on that. But a Startcom Certificate on a personal web
> site is one web site more that doesn't train users to blindly click
> away certificate warnings. A cacert certificate or a self-signed
> certificate on a personal web site is one web site more that does that
> kind of training.

Do you really think that the content on a Startcom certificated site is
more likely to be trustworthy than an CAcert certificated site?

I think the real problem here is the user interface asking one to trust
a site (forever, unless you're concentrating) at a point where you
really don't care because all you're interested in is seeing the cute
picture of an otter on someone's blog.

If browsers treated all new certificates with suspicion, limiting the
things that could be done in javascript, and not allowing forms to be
filled in, say, and then when you decided that you wanted to offer the
site some trust (because you want to fill in your credit card on the
https://amazon-really-it-is.mafia.biz/ site) the browser could then
guide you toward some checks that you might want to perform before
continuing, and because you've got a credit card n your hand you might
be vaguely interested at that point.

Anyway, can we not just have a cacert-certificates package, and then
people like me, who use cacert, could decide to trust them easily on my
machines at least?  If we instead do things that make it harder for even
Free Software enthusiasts to use something like CAcert, then the slim
chance that CAcert might eventually become properly useful gets even
slimmer.

Cheers, Phil.
-- 
|)|  Philip Hands [+44 (0)20 8530 9560]    http://www.hands.com/
|-|  HANDS.COM Ltd.                    http://ftp.uk.debian.org/
|(|  10 Onslow Gardens, South Woodford, London  E18 1NE  ENGLAND

Attachment: pgpJ6UJ7oaV0Q.pgp
Description: PGP signature


Reply to: