|
|
|
|
|
by rektide
2078 days ago
|
|
If anyone has been citing no examples, imo, it's you. I have elaborated & elaborated & elaborated, & you have said nothing to contend with other than 'it's easy'. I disagree. I've tried to talk to that at length. You've left everything but your one happy easy path to modifying a cert untouched, not commenting on a single one of the difficulties I've raised. I think TLS was mis-designed for an in-appropriate & indecent form of security that does not give permissions to the most important actor. Leaving the CA store on the hard drive, free to be modified by the user & sys-ops in a judicious careful manner was respectful of systems agency, giving a wide range of respect to different ways systems might need to be operated. Now, there are very few permissible ways to modify behavior. The system has closed down, locked down, become less programmable, less configurable. This advancement of the unmalleable is, imo, notable, prominent, progressing (on a wide variety of fronts), & obviously bad. |
|