hi Sandy, On Sat, 23 Apr 2011, Sandy Harris wrote: > > Arguably, the whole certificate infrastructure for SSL is broken > beyond repair. My /etc/ssl/certs has 289 Certificate Authorities > listed. These are not just people I am expected by default to trust; > they can sign certificates that make me trust others. > > Among other problems, many CAs are run by government agencies, some > by governments with policies antithetical to the box.
I'm not sure if you heard of FOAF+SSL before, to me it seems a good way to go, see http://www.w3.org/wiki/Foaf+ssl FWIW here is my contribution for a solution that secures GNU/Linux users' desktop with fairly strong encryption and educates them to keep their keys separated: http://tomb.dyne.org (it comes from a system already working in dyne:bolic 10 years ago which was already very useful in some crisis zones..) ciao -- jaromil, dyne.org developer, http://jaromil.dyne.org GPG: B2D9 9376 BFB2 60B7 601F 5B62 F6D3 FBD9 C2B6 8E39 Send bitcoins to: 1EJYtvuq39hoWcventcnnvhPXh6i5QDReM
signature.asc
Description: Digital signature
_______________________________________________ Freedombox-discuss mailing list [email protected] http://lists.alioth.debian.org/mailman/listinfo/freedombox-discuss
