lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-ID: <20100908192417.GC2207@sentinelchicken.org> Date: Wed, 8 Sep 2010 12:24:17 -0700 From: Tim <tim-security@...tinelchicken.org> To: BMF <badmotherfsckr@...il.com> Cc: Full Disclosure <full-disclosure@...ts.grok.org.uk> Subject: Re: [GOATSE SECURITY] Clench: Goatse's way to say "screw you" to certificate authorities > Amen. This is why we should use and support web of trust style systems. Webs of trust could definitely make SSL's PKI more fault tolerant. The hard part is figuring out how to make it work while users don't have to put forth any additional effort. Thoughts? tim _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/