It's bad that it's run by corporations, but it's still a good thing overall. Maybe it should be run by different people(like IDK ICANN over something like the UN)
It's bad that it's run by corporations, but it's still a good thing overall. Maybe it should be run by different people(like IDK ICANN over something like the UN)
OTOH SSL has done nothing for preventing phishing, since no CAs actually verify anything beyond you owning the domain.
Also, “remember this cert forever” (cert pinning) has been an ops disaster for a lot of sites that have tried it. So in practice “the first time” might be more like every week or every month. What the risk that a coffee shop will not serve you a malicious cert once a week?
Also if they do it and you move back to your home connection… the site is broken there because now it’s returning a different one than was pinned (by the attacker!).
I think a good idea might be to have TOFU and self-signed only as a fallback. If there was no initial mismatch, and then upate cert periodically.
All the little green lock icons in the world haven't put a dent in phishing or spoofing.