Comment on QubesOS workstation + homeserver, and DANE for TLS without 3rd party company
hirihit640@sh.itjust.works 3 weeks agoIf you’re just pushing for WebPKI without “thinking too hard” about perpretrating a system of centralized trust on government-controlled entitites, then you’re following that windows method.
SSL/TLS have very specific benefits. None of which matter that much for reading random articles on the web. So I don’t see the problem with this website doing their own thing to bring attention to the potential issues of the current system.
WhyJiffie@sh.itjust.works 2 weeks ago
it is a huge benefit if a man in the middle cannot run scripts on your computer.
there is no problem with that. this could work, with the required patch to firefox, also in the repo.
hirihit640@sh.itjust.works 2 weeks ago
IMO when reading random articles on the internet you already have to worry about untrusted scripts. I just use NoScript, and if the website requires Javascript I move on
WhyJiffie@sh.itjust.works 2 weeks ago
I don’t agree, I think there is a difference in likely outcomes. but even without scripts, you don’t want you article’s content (text, images, statements or names) be falsified by an attacker. Unless you are just reading the article to waste time, and magically what you read will not influence your views.
hirihit640@sh.itjust.works 2 weeks ago
I already considered that, and for an untrusted website I already don’t trust the content or the scripts. So it doesn’t matter if it was modified or not, it’s still untrusted.
Facts can be verified with sources you do trust (which should be using HTTPS). Logic can be used to verify others.