Subdomains + Development = Sucks: A quick tip from Kevin Hale of Wufoo
particletree.com
particletree.com
Alternatively, maybe most users don't pay attention to URLs or look at the distinction above in the same way we developers do.
Also, the subdomain strategy seems to have worked well for Blogger. They serve users' pages from *.blogspot.com, and their own pages from *.blogger.com.
One thing I really like about subdomains is that it makes accessing a site very quick... from my address bar I type "new" and news.yc.com pops right up!
On the positive side, your users will be cleanly sandboxed in separate domains, they get slash-free URIs, and you can have simple IP-based load balancing.
Any good stories about subdomains? Infogami?
User-created subdomains didn't seem like they really caught on until 37 Signals started having huge success.
These certificates have nothing at all to do with "authority." Just think about it, what exactly do they prove?
Why should you only be allowed to speak in confidence with well identified parties (not that verisign remotely attempts to identify anyone)? Think carefully.
Related: http://www.schneier.com/blog/archives/2005/12/new_phishing_tr.html
I don't see what's terrible about browser makers trusting certain authorities. It's useful to the user, and there's more than one authority so less chance of abuse. The only alternative is no authorities, or a government bureaucracy issuing them. I don't see how either of those 2 options is superior to the current situation.
There's nothing stopping you creating a free Certification Authority, it's just that you'd have to persuade the browser makers to trust you.
Because the authorities trust anyone who pays them 20 bucks. THEN, the users trust any site where the address bar turns yellow. Do you see the break in the chain here?
Then you switched to say that you can't really trust Authorities. Maybe so, but the current setup seems better to me than the alternatives.
Second, my argument has always been that the browser should not harass the user of a site that has not taken part in this PHONY identification procedure.
Heck, even google adsense has seen through this scam and not bothered to pay the fee.
Edit: To clarify, most users equivocate signed SSL certificate == trustable site. That is WRONG. Verisign does not vigorously establish the non-evilness of your site.
Example: http://blog.washingtonpost.com/securityfix/2006/02/the_new_face_of_phishing_1.html
Anytime you use a self-signed certificate [edit] without manually verifying the fingerprint of certificate [/edit] ANYONE who controls the network hardware between you and the second party can eavesdrop and even tamper with the communication stream. Neither you nor the second party has any way of knowing what's going on. That's why we NEED a warning every time we encounter a self-signed certificate.
The default behavior of the browsers is fine and we're lucky that the design allows us to fool around with self-signed certificates at all.
EDIT: If you manually verify the fingerprint of the self-signed certificate each time you connect you can be sure your connection is secure. But still the UI makes sense (even more sense).
I believe that you misunderstand the technology.