Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This is not true. There is no cryptosystem we know of that is more suited to "User Case 3" than TLS. There is a problem with the way activists in Iran are using TLS: to wit, they are trusting Mozilla, Microsoft, Apple, or Google to make decisions about who they trust. But TLS does not require them to do that. They are a point-and-click HOWTO away from not being in that position.

If Iranian activists want to trust Google for their sensitive email, all they have to do is track down Google's authentic certificate (by asking anybody outside of Iran to fetch it) and add it to their browser. Iran does not have the ability to break RSA. All they (apparently) have the ability to do is to con incompetent CAs into making new RSA signatures that some browsers are configured to believe.



If Iran is intercepting gmail traffic, they won't be able to access the real site regardless of whether they know about it.


They may not be able to access it but they will not mistakenly trust the wrong certificate if they take the steps that Thomas outlined.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: