|
|
|
|
|
by Godel_unicode
2078 days ago
|
|
I'm aware that you think that. What I'm struggling with is, in the face of all the evidence in this thread and others, why. This stuff is easy. It's well documented. There are YouTube videos literally (like, literally literally) walking through every step of the process. The fact that you specifically do not know how to do it right now doesn't mean it can't be done, or even that it's hard. The fact that your argument is "who knows about..." and not a specific example is a big clue that you might be baselessly worried about the sky falling. You claim that users are walled off, yet you haven't produced a single example of that being true. The fact that the cost to exploit end user devices in an irreversible, hard to detect way has been raised is a real benefit to the user. The fact that mitm of banking apps is very difficult without protracted user interaction is a real benefit to the user. There are, conservatively, hundreds of millions of users having their lives made better by security people fighting for them every day to make their devices safer to use in a hostile world. Do you also object to TLS? What about centrally generated electricity? |
|
I think TLS was mis-designed for an in-appropriate & indecent form of security that does not give permissions to the most important actor.
Leaving the CA store on the hard drive, free to be modified by the user & sys-ops in a judicious careful manner was respectful of systems agency, giving a wide range of respect to different ways systems might need to be operated. Now, there are very few permissible ways to modify behavior. The system has closed down, locked down, become less programmable, less configurable. This advancement of the unmalleable is, imo, notable, prominent, progressing (on a wide variety of fronts), & obviously bad.