101 karma · joined March 30, 2023
> 1. To cause physical damage or pain to (an individual or a body part); injure.
> 2. To experience injury or pain to or in (an individual or a body part).
> 3. To cause mental or emotional suffering to; distress.
Does looking at them cause you mental or emotional suffering?
What if I said that it caused me the same mental or emotional suffering anytime anybody wore a tshirt? Would you also say people should only wear tshirts inside?
This is part of the discrepancy - one side shoves the 15% number at everybody while the other side shoves at 45% number at everybody - we can't agree on what we're measuring.
See e.g. http://allhomekc.org/wp-content/uploads/2019/07/Updated-7.11...
Edit: not to mention that these studies are all surveys and this political issue is pretty well known, so there is a strong incentive to lie.
In examples:
- "summer is the best season" is an opinion
- "summer has the highest temperatures" is a fact
- "summer is the best time to have romantic encounters" is an opinion
- "summer is the best season because romantic encounters truly only happen in the summer" is a weird amalgamation. It clearly presents an opinion, and says that opinion is based on a true fact, but in fact, the true fact the opinion relies on is not a fact at all, but merely another opinion.
I think the simplest explanation for why representatives vote the way they do is the public statements they themselves make before and after their votes. If you want to make a more convoluted argument and assert a conspiracy, you should bring some evidence.
It's not quite so understandable to me that somebody would believe that position to be an inherent truth ("truly owe") rather than just a position.
Capital gains taxes have historically been lower to encourage the investment of capital. This might be good or bad policy. Many economists say it's good policy.
It's stating opinion as fact.
Particularly when the software in question is running on somebody else computer, proprietary software and OS (or OS modules), unknown patch versions, etc.
You're not a fan of DNSSEC and prefer CT. When faced with examples where CT doesn't cut it, you refuse to discuss the big picture, pounce on incorrect details, and then resort to claiming your opponents are uninformed or arguing in bad faith.
The bottom line is my original big picture claim, the part that's on-topic for the article - that CT works for browsers on personal computers but not other classes of internet connected devices - it's true! And you know it! But you'd rather debate the details than inform readers about what they actually want to know (the big picture - i.e. that DNSSEC is useful).
I've observed your behavior before on hacker news, but experiencing it directly is eye opening.
This is a false dichotomy. DNSSEC secures DNS records, it doesn't prevent logging certificate issuance.
It's late and I maybe haven't been super constructive here, but I think when you try to write out the actual assumptions behind CT as the whole solution, you realize you've got something that mostly works assuming assuming assuming - and worse, we'll never do any better, because those assumptions are fundamental technical limits. DNSSec may be ugly but at least its problems (like validators failing open) are just deployment issues, not fundamental technical issues.
I'm sick and tired of using technologies that provide security or correctness subject to a long list of preconditions and ways for folks to tell me I'm using it wrong. To build secure systems, we need technology that provides correct security without so much asterisks and fine print.
I want a version of Web PKI strong enough that I can turn off my tablet for a year, turn it back on in a coffee shop, apply automatic updates, and not have my web traffic monitored, even if I'm gay and the coffee shop is in Saudi Arabia.
From what I can see, DNSSec+CAA+.com+US CA+US hosting for the Android update server does the trick. No version of CT does.
> The fundamental difference is that with TLS you have to trust ALL certificate issuers, but with DNSSec you only have to trust your TLD and your certificate issuer.
It's probably fair to say I've been a bit over assertive about CT, but it's all in the margin to me. No amount of technical complexity can turn community trust into direct trust. TLS is a community trust model and DNSSec is a direct trust model. The fact that CT is a pretty good community trust model and that browsers have (so far) done a pretty good job at keeping the CT community small is interesting, but it doesn't turn community trust into direct trust. So while I'd agree it's an incredibly tedious tangent, I'd say it's tedious moreso because the pro-CT folks are missing the forest for the trees than for any technical details about CT.
Edit: because community trust fundamentally relies on the notion of the community taking action against bad actors. Whether it's a CA or a CT log provider, and whether it's malicious action or a bug or just ceasing to do business, community trust has a time axis where membership in the community changes and notions of keeping devices up to date and political struggles ("too big to fail") and the like that simply aren't needed in direct trust.
> Certificate transparency is cool, but it's not clear it really works for many classes of devices
Smart TVs aren't some gotcha I'm throwing in at the end. It's literally the first thing I said about CT. CT works ok for mobile phones, laptops, and other devices where you can make certain assumptions about multiple networks and frequent updates. If you want a technology that doesn't require these assumptions, you want DNSSec.
> If the installed version of Chrome has not applied security updates and has been unable to obtain an updated CT log list from the Component Updater for 70 days or more, then CT enforcement will be disabled.
That means a global adversary need merely block the update channel to targeted devices and wait. How will a Smart TV behave?
So... Governments like the US and China can fake the entries by using their police forces to seize the private keys?
SCT has the same set of problems as TLS - any log will do, not just logs from countries you trust.
Why do you think this isn't possible?
The fact remains - an adversary with a CA private key that can mitm all of the internet connections for a device can forge a fake CT log and go undetected, if that clients never uses a non-mitm network again.
Such an attack would be detected if some clients reported which certs they actually saw the next time they connected to an uncompromised network (as Chrome does) but if no clients report, such an attack could go undetected.
For a device like a router, if the router doesn't check the logs itself, and a global adversary compromises the TLS update channel for the router, and starts distributing malicious firmware... If the router itself doesn't report the violation, for how long might such a compromise go undetected? Is there any reason to think it'd ever be detected?
CT has a bit of an implicit dependency on heterogeneous configurations - that at least some clients report violations, and that attackers cannot easily distinguish reporting clients from non-reporting clients. For homogenous configurations (like the implementations of AWS, Azure, or GCM, or the deployment of routers, IOT devices, or gaming systems), it seems like a competent global adversary would simply figure out how to go unreported for that configuration, and nobody would particularly check.