Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.project > #9330
| From | Adam Borowski <kilobyte@angband.pl> |
|---|---|
| Newsgroups | linux.debian.project |
| Subject | Re: No port 443 (https) available at "security.debian.org"-repository |
| Date | 2017-07-26 01:20 +0200 |
| Message-ID | <u7hhn-SP-9@gated-at.bofh.it> (permalink) |
| References | <u7f5U-7HQ-27@gated-at.bofh.it> <u7f5U-7HQ-25@gated-at.bofh.it> <u7gv0-lh-11@gated-at.bofh.it> <u7hhn-SP-11@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
On Wed, Jul 26, 2017 at 07:01:36AM +0800, James Bromberger wrote: > On 26/07/2017 6:20 AM, Adam Borowski wrote: > > https provides no protection against targetted attacks by government agents. > > The CA cartel model consists of 400+ CAs, many of them outright controlled > > by governments, most of the rest doing what they're told (no, warrants are > > are a story for nice kids). Clients in general trust _any_ CA, which means > > you're only as secure as the worst CA. Ie, https protects you against Joe > > Script Kiddie but not against a capable opponent. > > Except there are new-ish ways to limit the scope from 400+ CAs to just > the one you use. > c.f. > /Certification Authority Authorization/ (/CAA/) /DNS/ Resource > https://tools.ietf.org/html/rfc6844 > > ... if APT wishes to support this. This one is meant to be used only by CAs. And a rogue CA has no reason to obey this request (especially if it _normally_ obeys it). For users, the equivalent is TLSA, which allows both CA constraints and specifying a fingerprint of the certificate itself. -- ⢀⣴⠾⠻⢶⣦⠀ What Would Jesus Do, MUD/MMORPG edition: ⣾⠁⢰⠒⠀⣿⡁ • multiplay with an admin char to benefit your mortal ⢿⡄⠘⠷⠚⠋⠀ • abuse item cloning bugs (the five fishes + two breads affair) ⠈⠳⣄⠀⠀⠀⠀ • use glitches to walk on water
Back to linux.debian.project | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
Re: No port 443 (https) available at "security.debian.org"-repository Chris Lamb <lamby@debian.org> - 2017-07-25 23:00 +0200
Re: No port 443 (https) available at "security.debian.org"-repository Peter Palfrader <weasel@debian.org> - 2017-07-25 23:00 +0200
Re: No port 443 (https) available at "security.debian.org"-repository Adam Borowski <kilobyte@angband.pl> - 2017-07-26 00:30 +0200
Re: No port 443 (https) available at "security.debian.org"-repository Adam Borowski <kilobyte@angband.pl> - 2017-07-26 01:20 +0200
Re: No port 443 (https) available at "security.debian.org"-repository James Bromberger <james@rcpt.to> - 2017-07-26 01:30 +0200
Re: No port 443 (https) available at "security.debian.org"-repository Ondřej Surý <ondrej@sury.org> - 2017-08-04 14:10 +0200
csiph-web