I'm waiting for the first carrier to perform SSL MITM.
I'm waiting for the first carrier to perform SSL MITM.
Quote from someone working for a satellite internet provider for airlines.
Source: http://www.atis.org/openweballiance/docs/OWAKickoffSlides051... page 27
Nokia, funnily enough, did this on certain dumbphone models. Not a carrier, I know, but still interesting.
Yeah...except the NSA-agent-hiring IETF [1] gave up on that at the last minute.
http://arstechnica.com/security/2014/01/nsa-employee-will-co...
If a certificate is compromised, changing it means all pinned clients will get a huge warning. Either the user ignores the warning (in which case pinning is useless) or he doesn't and the site is harmed. Keeping a compromised certificate is even worse.
For WoT you first need a web of trusted individuals.
Unfortunately key distribution over insecure channels is still an unsolved problem.