Search found 7 matches

by cryptosile
Tue Sep 09, 2014 5:00 am
Forum: Domain Names / Dot-Bit
Topic: Freespeachme .bit SNI
Replies: 5
Views: 7380

Re: Freespeachme .bit SNI

I think in the coming years SNI will become much more prevalent. So I think the question really should be to prove why SNI shouldn't be implemented rather than to try and prove why it should. I guess I could use the host IP fingerprint.... I'm essentially trusting them anyways.... somehow it doesn't...
by cryptosile
Tue Sep 09, 2014 4:55 am
Forum: General Discussion
Topic: Why the certificate system is broken
Replies: 7
Views: 5589

Re: Why the certificate system is broken

I completely agree the current CA system is broken, I just don't take the absolute stance that any system that relies on trust is "broken" . there are just things that can't be done otherwise. That doesn't mean we can't strive to make things as trust less as possible. I'm just trying to be realistic...
by cryptosile
Sun Sep 07, 2014 1:56 am
Forum: General Discussion
Topic: Why the certificate system is broken
Replies: 7
Views: 5589

Re: Why the certificate system is broken

Thanks for the feedback. Blunt is good. In retrospect I did take about 10 minutes to basically say there are too many CA's. On the issue of trust, trust-less is always better but it doesn't mean the systems that require trust are broken. I came to this conclusion after considering the fact that ever...
by cryptosile
Sat Sep 06, 2014 9:41 pm
Forum: Domain Names / Dot-Bit
Topic: Freespeachme .bit SNI
Replies: 5
Views: 7380

Re: Freespeachme .bit SNI

Thanks for taking a look! I did it!!! Yeah!!! I finally got freespeechme to say verified!! I've confimred that SNI is what is causing problems with FreeSpeechMe. Meowbit, as far as I know doesn't do any verification of the certificate. (someone correct me if i'm wrong here.) Freespeech me is much mo...
by cryptosile
Sat Sep 06, 2014 6:01 pm
Forum: Domain Names / Dot-Bit
Topic: Freespeachme .bit SNI
Replies: 5
Views: 7380

Freespeachme .bit SNI

man... i'm i'm starting to go crazy here... I thought I'd be able to get some SSL validation through namecoin by now. See my other post for trying to get DANE + DNSChains working. Now, I'm just trying to get simple fingerprinting through freespeechme working. My fresspeechme client works fine for ht...
by cryptosile
Sat Sep 06, 2014 2:12 pm
Forum: Domain Names / Dot-Bit
Topic: DNSChains + DANE Validator for sile.bit
Replies: 1
Views: 4570

DNSChains + DANE Validator for sile.bit

Has anyone been able to get DNSChains to build the correct DNS records to make DANE validation actually work? I've tried to validate with danetool from gnutls: It says it can't find any TLSA record, however, with wireshark I can see it pull down the TLSA record successfully. I've also tried this web...
by cryptosile
Sat Aug 30, 2014 2:12 am
Forum: General Discussion
Topic: Why the certificate system is broken
Replies: 7
Views: 5589

Why the certificate system is broken

I made a video talking about why the certificate authority system is broken. Hopefully it can be used to be explained why namecoin is important. I'm working on a follow up video as well that describes how namecoin works to solve the problems in the current CA system. https://www.youtube.com/watch?v=...