Convergence, distributed, secure strategy replacing certificate authorities
convergence.io
convergence.io
https://grepular.com/Solving_the_SSL_CA_Debacle_Using_Multi-...
The problem is that the industry prefers it the way it is.
Please view this blog entry (from the core author of convergence.io) to get the idea of also why DNSSEC is not a good approach (he had put it in the way that it's worse than CAs.)
The only reason why my mum won't be tricked into adding a rogue CA root is because it's too complicated to do for her, even if she wanted to.
* If it was as easy as installing a fake Flash plugin Trojan, she'd have installed plenty of rogue CAs already; * If it remains hard to do, she'll stick to the default config, which is what she does already.
So, the main change wrt the current PKI system is that by default, her browser would probably check a certificate validity against a couple of top authorities, rather than a single one. I guess it would make getting a certificate a couple of times more complicated, hence a couple of times more expensive (if the process of trust propagation is fully automated, then I'm no safer than with a single CA signature).
To sum up, I don't see how this would improve the situation for average Joes and Janes. Since Paypal, Amazon, Google etc. primarily care about average Joes, I don't see why they would adopt that kind of cyberpunk technology.
That's how the DigiNotar breach was publicly disclosed. The browser/CA CAB forum knew about it and had been hiding it for weeks until an actual Chrome user posted a message in the Gmail support forum: https://www.google.com/support/forum/p/gmail/thread?tid=2da6...
That's really criminal.
The problem with the CA system is that the default config is already unsafe, let alone robust, as evidenced by major browsers hastily releasing new versions to be able to revoke trust in a single CA. Jane McNewbie goes to sleep every night without a worry on her mind while the Comodos and Diginotars of this world make mistake after mistake. Is that really so much better?
> So, the main change wrt the current PKI system is that by default, her browser would probably check a certificate validity against a couple of top authorities, rather than a single one. I guess it would make getting a certificate a couple of times more complicated, hence a couple of times more expensive (if the process of trust propagation is fully automated, then I'm no safer than with a single CA signature).
You guess? Have you actually looked at Convergence?
In two words, 'trust agility' as they say in the website.
I like the idea, but I know too few people who will really start using it.
People that value their internet security and are disappointed by the current SSL trust system.
I'm sure it will have to see a lot of testing by interested power users first, before it is ready for prime time / default integration into browsers.
Nevertheless, I think it is a very interesting development as it is much more realistic than the current trust system. Trust is no longer something absolute, eternal, dealt out by somehow globally fully trusted entities.