hi Sandy,

On Sat, 23 Apr 2011, Sandy Harris wrote:
> 
> Arguably, the whole certificate infrastructure for SSL is broken
> beyond repair. My /etc/ssl/certs has 289 Certificate Authorities
> listed. These are not just people I am expected by default to trust;
> they can sign certificates that make me trust others.
> 
> Among other problems, many CAs are run by government agencies, some
> by governments with policies antithetical to the box.

I'm not sure if you heard of FOAF+SSL before, to me it seems a good
way to go, see http://www.w3.org/wiki/Foaf+ssl

FWIW here is my contribution for a solution that secures GNU/Linux
users' desktop with fairly strong encryption and educates them to keep
their keys separated: http://tomb.dyne.org (it comes from a system
already working in dyne:bolic 10 years ago which was already very
useful in some crisis zones..)

ciao


-- 
jaromil,  dyne.org developer,  http://jaromil.dyne.org
GPG: B2D9 9376 BFB2 60B7 601F 5B62 F6D3 FBD9 C2B6 8E39
Send bitcoins to:  1EJYtvuq39hoWcventcnnvhPXh6i5QDReM


Attachment: signature.asc
Description: Digital signature

_______________________________________________
Freedombox-discuss mailing list
[email protected]
http://lists.alioth.debian.org/mailman/listinfo/freedombox-discuss

Reply via email to