Hacker News new | ask | show | jobs
by unixbane 1541 days ago
HTTPS is when you ask 200 companies if either of them know the key for your bank. And they are all run by charlatan boomers who think buying more firewalls and cool security products is equivalent to securing their private cert signing keys. Why on earth would I ever want this? Like hello, have you ever seen ultracorporate tech company culture? They really don't know what they're doing. Why would you trust them let alone trust 200 of them in a way such that even if one of them messes up, all your sites are compromised?

Imagine that domain names contained the public key in them. I Google up "mybank", and it gives me https://8c789ad256afa4ca93f1af6436e7adff51cdd1c380de7d7cc78b... This takes <1000 lines of code to implement and already stops the only thing that HTTPS stops: a noob MITM positioned attacker who can't break into CAs. The MITM can't change the Google results, because you already came from https://a4244aa43ddd6e3ef9e64bb80f4ee952f68232aa008d3da9c78e..., which you somehow obtained before the MITM happened.