Matt Blaze on Applied Cryptography, 15 years later
crypto.com
crypto.com
I want to use it but that means someone else has to be using it also.
On a related note, I was chatting to a friend the other week, and he was using Off The Record(it's encryption of IM), now I had gone to the trouble to install it on my machine but he was using Adium and it came default, he didn't even know he was using it. Good job Adium.
Cryptography has failed.
I think the right way to go is for providers make strong cryptography standard (like your Adium example). The current GPG usage model and its integration with email is poorly executed, and most of the web-using public won't care to learn how it works let alone create key pairs. The only thing the public at large can understand is secrecy of social communication. I await the day Facebook or Google start automatically generating and managing keys, and encrypting communication between users based on their social connections.
... ok, back. So, what you're saying is:
* Mozilla shipping a stale RSA-owned certificate shows that SSL has "broken down", and/or
* Kurt Seifreid allegedly managing to get RapidSSL to issue a cert for "a webmail provider" by signing up for the account "ssladmin" shows that SSL has "broken down".
Gotcha. Have you considered asking the banks, retail brokerages, and trading exchanges to stop relying on SSL, because it's so clearly broken?
I'm sorry for the sarcastic response, but this faux controversy gets tiring.
Just be glad you're not in vaccination business. ;-)