PowerCrazy

joined 1 year ago
[–] [email protected] -4 points 1 year ago (3 children)

Why? There is absolutely zero risk in SSHing into "random" machines especially since I'm using public ssh-keys. Of course the first time I connect to a machine it's going to be untrusted, but who cares? I'm using SSH to ensure others can't sniff my traffic.

[–] [email protected] -5 points 1 year ago (1 children)

I don't really care if a site is who they say they are, I'm the one connecting to the site, if the site does what I expect, they are serving their purpose. The only thing I use SSH/HTTPS for is to make sure that whatever communication between me and the site can't be snooped. A CA allows a third party to snoop that traffic, and I have no indication they are doing it.

[–] [email protected] -3 points 1 year ago (1 children)

Eh, they do want to maximize profits, but this is more about fighting back against the EU basically making their business model illegal not making their service worse in favor of profits.

[–] [email protected] -5 points 1 year ago (5 children)

That's where the SSH analogy comes from. On the initial connection you get the signature of the web-site you are trying to visit and your browser trusts it from then on. If something changes later, then the scary warning comes up.

[–] [email protected] 8 points 1 year ago (17 children)

Centralized CAs were and are a mistake. HTTPs should work more like ssh-keys where the first time you connect to a website it's untrusted, but once you have validated it the website you want, it never bothers you again unless the private key changes. Private key rotations can be posted on public forums, or emailed, or any number of other ways and users that don't care can ignore the warnings like they do anyway, while users who DO care, can perform their own validation through other channels.

The most important aspect is that there is no "authority" that can be corrupted, except for the service you are connecting to.

[–] [email protected] 1 points 1 year ago (1 children)

If he only follows them through Instagram it's most likely a para-social relationship, and not a real friend at all.

view more: ‹ prev next ›