On Tue, 1 Nov 2005, Julien Pierre wrote:
> Ka-Ping Yee wrote:
> > What fraction of the 30 to 50 root CAs on your root CA list do you
> > know or have ever heard of?  Do you know their policies?  Do you know
> > their management?  Why should you trust them?
> >
> > What makes a website legitimate is the fact that it is the website
> > you truly intended, not the fact that it happens to have paid a member
> > of the CA extortion ring.
>
> What other way does the average non-technical user have to know that the
> secure website is the one truly intended and not a fake, except than to
> rely upon a third party to do the verification for them ? Self-signed
> certs certainly don't provide any of that type of assurance.

What matters is that the certificate represents the *same* organization
you created the account with, not that the certificate was purchased
from a particular company.  Browsers should help users keep track of
these identities, using mechanisms such as the petname toolbar, instead
of showing more warning dialogs or making warnings more severe.

Using a petname field to label a website is really no different than
assigning names to your IM buddies, which people already do.  Why doesn't
impersonation work on IM? [*]  Because your buddy list keeps track of who
you know.  It can be the same way, and just as easy, with Web browsers.


-- ?!ng

[*] If your IM protocol is not encrypted, you are vulnerable.  Compare
    apples to apples, though: the analogy is between encrypted IM and
    browsing the Web with SSL.
_______________________________________________
mozilla-crypto mailing list
[email protected]
http://mail.mozilla.org/listinfo/mozilla-crypto

Reply via email to