Well, I have seen that trust-list in the browser before and it's too long.
Ideally the user should have to build it based on information received via some other transport, like a "cert card" from the bank, google, e.t.c.
But that's just in-practical, I somehow think they should follow the dns system in trust path. ".com" is signed with root, "somesite.com" is signed with ".com".
But I do not think it would solve a lot, unless it can be done localized.
This has been flagged as spam show
Mikko and Sean are answering your questions in the online F-Secure Community on December 5-9.2011
ANKU1983 2 months ago
Well, I have seen that trust-list in the browser before and it's too long.
Ideally the user should have to build it based on information received via some other transport, like a "cert card" from the bank, google, e.t.c.
But that's just in-practical, I somehow think they should follow the dns system in trust path. ".com" is signed with root, "somesite.com" is signed with ".com".
But I do not think it would solve a lot, unless it can be done localized.
Maybe SSL should be like PGP keys?
Tricky.
erlendse 9 months ago