Back to News
Advertisement
Advertisement

⚡ Community Insights

Discussion Sentiment

33% Positive

Analyzed from 170 words in the discussion.

Trending Topics

#tls#bad#ietf#https#client#random#website#sounds#interesting#text

Discussion (6 Comments)Read Original on HackerNews

duk3luk3•about 2 hours ago
Sounds interesting; too bad all we get is text made up by an LLM rather than any of the author's insights.
abound•about 2 hours ago
Yeah I was interested for the first few paragraphs, then all of a sudden I get hit with two "genuinely"s and a

> That’s the third property, and it’s the one that decides this.

and I gave up at that point.

ram_rattle•about 1 hour ago
Nothing new here, attested TLS was being discussed in IETF for quiet sometime right?

https://datatracker.ietf.org/doc/draft-fossati-tls-attestati... https://www.youtube.com/watch?v=MF9AwkMJOlw

ranger_danger•about 2 hours ago
Let's hope this doesn't get picked up by the (corporate) masses... the last thing I want is my browser offering personal TLS certificates to every server I visit as some kind of identity verification or fingerprint/tracking.

It's bad enough that ssh does this by default with all your keys.

altairprime•36 minutes ago
Client TLS is rather unusable on the Internet by a typical random end user visiting a random public site, so that should at least keep the specific scenario you describe at bay.
ranger_danger•15 minutes ago
Currently yes, but there's not much stopping Chrome etc. from adding a new feature that has a way of presenting a client certificate to a website in a backwards-compatible manner.

Of course the website itself would need to support that, but it's all possible in time.