Philip Hands <[email protected]> writes: > On Tue, 10 Jan 2012 21:55:18 -0600, Nick Daly <[email protected]> wrote: > >> Monkeysphere /could/ help automatically organize an HTTPS connection >> between the server and client (after key exchange), had they completed >> their listed goals. That's not the case, though, so it can't be done. > > Isn't this all just unnecessary complication -- once a trusted connection with > your browser to the HTTPS server on the FB, you'll have to accept it's > key (clicking the pointless overrides) -- at that point the FB could > issue you with a client cert (or just use passwords for authentication, > or both -- whatever you fancy). > > Once that's done, your browser will notice a change of server key -- we > may need to recommend that people install a plugin to make sure that they > get the message that that's a Bad Thing.
You have a very good point. My concept was unnecessarily complicated, which /is/ the last thing we want. It would be nice to use client certs, to save the password typing, but that's just convenience. It might still be interesting to give FBXs their own PGP key (mutually signed by their owners'), to allow FBXs to communicate directly between themselves over the WOT. That could produce amazing (and unexpected) results. Nick
pgpDsBFY2pyTz.pgp
Description: PGP signature
_______________________________________________ Freedombox-discuss mailing list [email protected] http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/freedombox-discuss
