I am just wondering if this level of unstoppable infection is just going to be it, or are we at the pre-cellular structure of life point in the internet?
I am just wondering if this level of unstoppable infection is just going to be it, or are we at the pre-cellular structure of life point in the internet?
It's a quite fascinating re-imagination of the Internet, solving many of its problems (and probably introducing a whole slew of new ones).
Even now as it is it's worse than it should be: I can't control which pairs of (address,certificate) will be allowed to be accepted for specific sites. Instead, every browser vendor allows any "man in the middle" with the access to any CA (and CA's are known to be very bad(1)) to insert itself between my own server and my own client.
1) Read and weep: https://arstechnica.com/information-technology/2018/03/23000...
This should be a basically available scenario for the secure connection, just like what we have in SSH. Don't believe "the users are too stupid" excuse. It's just an excuse:
https://golem.ph.utexas.edu/category/2014/10/new_evidence_of...
We simply shouldn't have to have the "trust in every crooked CA" when we connect to the servers we directly know.
That way a website owner can whitelist only a very specific CA for their certificates.
Ideally with DNSSEC we could also get DANE and issue our own certificates and CA's would only be necessary as cosigner for OV, EV and similar.
I don't think it would help with the initial compromise of the router either. Buffer overflows (for example) can be exploited over https just as well as http, and that would be similar for other cryptographic strategies.