<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title>Noah's Mark - Latest Comments in Firefox&amp;#8217;s SSL policy is not bad, you idiot</title><link>http://noahsmark.disqus.com/</link><description></description><atom:link href="https://noahsmark.disqus.com/firefox8217s_ssl_policy_is_not_bad_you_idiot/latest.rss" rel="self"></atom:link><language>en</language><lastBuildDate>Sun, 13 Sep 2009 04:50:51 -0000</lastBuildDate><item><title>Re: Firefox&amp;#8217;s SSL policy is not bad, you idiot</title><link>http://noahsmark.com/2008/08/19/firefoxs-ssl-policy-is-not-bad-you-idiot/#comment-16532524</link><description>&lt;p&gt;Besides the funny &lt;a href="http://www.123-reg.co.uk/ssl-certificates/" rel="nofollow noopener" target="_blank" title="http://www.123-reg.co.uk/ssl-certificates/"&gt;ssl certificates&lt;/a&gt; messages Firefox is using, I also got another funny message when my browser crashed. It was something like this: "This is embarrassing...". When I first saw it I had to print screen it and send it to my entire messenger list. Now when I get it I'm as mad as hell because it happens at least twice per day. I finally upgraded. I really hope Firefox won't crash anymore.&lt;br&gt;&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">eddiepetosa</dc:creator><pubDate>Sun, 13 Sep 2009 04:50:51 -0000</pubDate></item><item><title>Re: Firefox&amp;#8217;s SSL policy is not bad, you idiot</title><link>http://noahsmark.com/2008/08/19/firefoxs-ssl-policy-is-not-bad-you-idiot/#comment-13701955</link><description>&lt;p&gt;I certainly appreciate your effort to make your grandma's internet exprience safe. ;-) However, there's one thing you're fundamentally getting wrong. Firefox's shiny little lock icon is some kind of special endorsement. So whenever the conditions for this endorsement are not fulfilled, just don't make it! Just treat it this web session like a normal unencrypted one. Where's the problem? Just leave out the lock symbol.&lt;/p&gt;&lt;p&gt;What Firefox does, however, is demonising SSL w/o trusted certificate while it is still, by orders of magnitude, more secure than not encrypting at all. This is nonsense.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Victor Hahn</dc:creator><pubDate>Thu, 30 Jul 2009 21:25:00 -0000</pubDate></item><item><title>Re: Firefox&amp;#8217;s SSL policy is not bad, you idiot</title><link>http://noahsmark.com/2008/08/19/firefoxs-ssl-policy-is-not-bad-you-idiot/#comment-2347808</link><description>&lt;p&gt;Good read. I think it's a good system to get in your face; especially for my relatives who are computer illiterate. This step is completely necessary to protect any user from doing harm to themself.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">PaulSolt</dc:creator><pubDate>Sun, 14 Sep 2008 13:23:55 -0000</pubDate></item><item><title>Re: Firefox&amp;#8217;s SSL policy is not bad, you idiot</title><link>http://noahsmark.com/2008/08/19/firefoxs-ssl-policy-is-not-bad-you-idiot/#comment-1668040</link><description>&lt;p&gt;Because they are different services - note the keyword _verification_ in that second part. The first part, the "I want a domain name here plzthx", isn't a complicated problem because there aren't many (enforced) trust/identity strings attached. Also, because there are an inordinate amount of domains being registered and a much smaller number of sites getting SSL certs, I can only imagine the cost for the first will be much cheaper than the second. Sounds pretty simple to me.&lt;/p&gt;&lt;p&gt;Oh, and the real answer is, "because they charge that much and people will pay it." Enter capitalism.&lt;/p&gt;&lt;p&gt;Your suggestion, in the first paragraph, is for how a "trusted" authority should establish trust with an untrusted endpoint - you do some activity to prove to that party that you "own" the domain, and that third party, which is a trusted authority by some other definition, is depended on for its verification of your site. Maybe that is enough to establish trust, but how does it relate to the post?&lt;/p&gt;&lt;p&gt;If you want to complain about the methods CAs use to verify identity, then that is a different discussion. If you feel a CA charges too much for its services, find a different one. The digicert price I found was after clicking 2 links in a google search. I bet you can find better prices without looking too hard.&lt;/p&gt;&lt;p&gt;Or you get behind someone like &lt;a href="http://CACert.org" rel="nofollow noopener" target="_blank" title="CACert.org"&gt;CACert.org&lt;/a&gt;, who gives out free (as in beer) certs and (I believe) is still trying to be accepted by mozilla as a trusted root CA:&lt;br&gt;&lt;a href="https://bugzilla.mozilla.org/show_bug.cgi?id=21" rel="nofollow noopener" target="_blank" title="https://bugzilla.mozilla.org/show_bug.cgi?id=21"&gt;https://bugzilla.mozilla.or...&lt;/a&gt;...&lt;/p&gt;&lt;p&gt;Mozilla has a nice, fair, and public policy for how to become a trusted CA:&lt;br&gt;&lt;a href="http://www.mozilla.org/projects/security/certs/" rel="nofollow noopener" target="_blank" title="http://www.mozilla.org/projects/security/certs/"&gt;http://www.mozilla.org/proj...&lt;/a&gt;...&lt;/p&gt;&lt;p&gt;So I don't think there are major roadblocks preventing somebody from using your method to establish trust and charging less than $100 a year and getting accepted by mozilla as a root CA. Except, you know, capitalism.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">noah</dc:creator><pubDate>Tue, 19 Aug 2008 23:50:44 -0000</pubDate></item><item><title>Re: Firefox&amp;#8217;s SSL policy is not bad, you idiot</title><link>http://noahsmark.com/2008/08/19/firefoxs-ssl-policy-is-not-bad-you-idiot/#comment-1667871</link><description>&lt;p&gt;Server identity verification can and should be tested in the same manner that Google Apps does it - stick a new page up on your server or add a new CNAME record to prove you control the domain.&lt;/p&gt;&lt;p&gt;If domain names can be registered for under $10, why should domain name verification cost hundreds of dollars per year?&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">trevelyan</dc:creator><pubDate>Tue, 19 Aug 2008 16:02:26 -0000</pubDate></item></channel></rss>