Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> are there things we can do right now in terms of favoring self-authentication of self-signed certs?

That's a good question, but I've yet to see any justification for thinking the answer is "yes".

If an attacker controls your network connection and/or DNS, what possible information could you obtain to prove the authenticity of a website, without reference to an external source of authority?



Agreed. That's why it was a question. :) I'm trying to get people to start thinking in that direction, rather than in a central source of authority (which also means DNSSEC or DNS TXT's are out)




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: