• 1 Post
  • 266 Comments
Joined 10 months ago
cake
Cake day: February 20th, 2025

help-circle
  • The point is, if the certificate gets stolen, there’s no GOOD mechanism for marking it bad.

    If your password gets stolen, only two entities need to be told it’s invalid. You and the website the password is for.

    If an SSL certificate is stolen, everyone who would potentially use the website need to know, and they need to know before they try to contact the website. SSL certificate revocation is a very difficult communication problem, and it’s mostly ignored by browsers because of the major performance issues it brings having to double check SSL certs with a third party.




















  • No, you can’t EASILY do that. You could spend a ton of research to design a machine, but you’d never get anyone to sign off that the design was proper

    You would also need a SKILLED technician to operate such a machine, and that would require someone with medical training to do so. The vast majority of people who spend significant time and money getting that training wouldn’t use it to kill people.

    So now you’re left with someone who wants to kill people, designing a machine with no oversight, run by someone who wants to kill people, with little or no training. That’s literally what’s happening now, and is the reason that people are looking for alternatives.