HN Theater @HNTheaterMonth

The best talks and videos of Hacker News.

Hacker News Comments on
USENIX Enigma 2016 - Several Horror Stories about the Encrypted Web

USENIX Enigma Conference · Youtube · 29 HN points · 0 HN comments
HN Theater has aggregated all Hacker News stories and comments that mention USENIX Enigma Conference's video "USENIX Enigma 2016 - Several Horror Stories about the Encrypted Web".
Youtube Summary
Peter Eckersley and Yan Zhu, Electronic Frontier Foundation

You would think that encrypting Internet protocols would be a simple matter of applying a trapdoor one-way function to all of your messages. In reality, encrypting the Web is a more sordid and byzantine undertaking. In this talk we will report upon a number of the more ghastly things we've encountered while working on the Let's Encrypt and HTTPS Everywhere projects, and on new methods you can use to stay safe and sane in this Lovecraftian world.

Sign up to find out more about Enigma conferences:
https://www.usenix.org/conference/enigma2016#signup

Watch all Enigma 2016 videos at:
http://enigma.usenix.org/youtube
HN Theater Rankings

Hacker News Stories and Comments

All the comments and stories posted to Hacker News that reference this video.
Feb 26, 2016 · 29 points, 7 comments · submitted by grey-area
joshuak
This is actually a great letsencrypt.org intro. Too bad it's not labeled that way here or on youtube.
nickpsecurity
Yeah, I suggest them changing the title to something that says it's letsencrypt. Had I not glanced here, I'd have totally skipped it thinking it was some scare tactics from security industry or government to push their agendas with.
baby
1. There are too many CAs

2. so let's create another CA!

The transition here was weird.

Also, there are now a HUGE number of certs signed by let's encrypt. Isn't that a problem? Remember Comodo now too big to get removed?

I guess let's encrypt cannot sign intermediate CA certificates and that's a good thing, and we should have more CA like that and less CA like Comodo. Also if they are free (I still find it mindblowing that you have to pay for certificates) and are quick to implement/respect new rules directed by the cabforum. Then it is an improvement of the current internet PKI.

Now what about better/other solutions to secure internet? I'm still scared of having to trust thousands of CAs that all have the same power.

kevin_thibedeau
> I still find it mindblowing that you have to pay for certificates

You pay for the CA to verify you are who you claim to be.

darklajid
For DV certificates: You pay a shitload of money for a single email.

Ignoring the sibling comment (most of these CAs aren't trustworthy as far as I'm concerned): The price is highly inflated and that translates to bile and disgust whenever I think of CAs or the CA model.

mirimir
But who verifies that the CA is who they claim to be?

Or is doing what they claim to do?

Maybe they've been hacked, or infiltrated, or sold out, or ...

If I'm American, do I trust Chinese CAs? Or vice versa?

c22
Presumably this is the job of browser vendors.
HN Theater is an independent project and is not operated by Y Combinator or any of the video hosting platforms linked to on this site.
~ yaj@
;laksdfhjdhksalkfj more things
yahnd.com ~ Privacy Policy ~
Lorem ipsum dolor sit amet, consectetur adipisicing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.