this post was submitted on 07 Apr 2025
364 points (98.1% liked)

Privacy

36771 readers
164 users here now

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

Related communities

much thanks to @gary_host_laptop for the logo design :)

founded 5 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] shortwavesurfer@lemmy.zip 14 points 1 week ago* (last edited 1 week ago) (3 children)

As far as Let's Encrypt goes, the easy way to solve that is self-signed SSL certificates and Tofu. Just make it stupid obvious if an SSL certificate changes on a site that you go to. Like, turn your browser into a giant red screen that says that the security of the website has changed and may be broken obvious. Maybe you could have search engines also index SSL certificates so you could see if Google and Bing and DuckDuckGo and whoever else all say that this website has the same SSL certificate that it has had for X amount of time and if the search engines start showing different results you get suspicious.

Edit: Using self-signed certificates and tofu fits better with the decentralized ethos of the original web anyway since you're not relying on some third-party authority to tell you what's safe and what's not.

[–] WhyJiffie@sh.itjust.works 3 points 6 days ago (1 children)

i don't think this is a good idea. govs could just set up a big reverse proxy for lots of sites to serve them with their own certs, and you wouldn't know

[–] shortwavesurfer@lemmy.zip 2 points 6 days ago

Seems like no change from right now, because currently the certificate authorities are centralized entities, which could be pressured by governments to add their own certificates.

[–] Petter1@lemm.ee 2 points 6 days ago (1 children)

How about a Blockchain or Directed Acyclic Graph (DAG) out of SSL certs 🤔

I think that would finally be a use case for that tech, lol

[–] shortwavesurfer@lemmy.zip 2 points 6 days ago (1 children)

A blockchain to verify ssl cert keys and changes may work. Though idk how consensus would be secured.

[–] Petter1@lemm.ee 1 points 5 days ago

If you issue a certificate, you proof ownership via * challenge–response test that is validated by each node. If x% (like eg. 70%) of nodes agree that the test is passed, the block counts as validated and can be placed onto the chain. (Each node places the block on their chain and the hash must be same as hash of chain of majority of nodes)

[–] marauding_gibberish142@lemmy.dbzer0.com 3 points 6 days ago (1 children)

Never heard of tofu before (the software). What is it?

I had heard about DANE and how that would help in scaling back the need for big CAs but I could never grasp how one would do that. Do you know about it? I'm looking for someone to explain it to me.

[–] shortwavesurfer@lemmy.zip 6 points 6 days ago (2 children)

Tofu stands for Trust on First Use. So basically, you would get an SSL certificate from the website the very first time you connected to it, instead of trusting a certificate authority. Then, if the SSL certificate changed, you would then be warned that the certificate had changed and would have to decide whether to trust the new certificate or not trust the new certificate. That's why I said perhaps search engines could index certificates and tell you how long the certificate has been active and you could check several engines quickly to determine whether each engine has the same certificate indexed for the same website and if they did not then you would know something might be up.

[–] Thorned_Rose@sh.itjust.works 3 points 6 days ago (1 children)

I don't feel like this adequately accounts for stupid people though. The number of times I've seen people freak out over a perfectly legit website because a cert warning popped up or others who have ignored the warning and clicked through to a scam or malware... 🤦‍♀️

[–] shortwavesurfer@lemmy.zip 1 points 6 days ago

Decentralization comes with some casualties, and stupid people might just be those casualties.

[–] marauding_gibberish142@lemmy.dbzer0.com 1 points 6 days ago* (last edited 6 days ago) (1 children)

Oh, this is certainly complex logic (for the search engine I mean).

[–] shortwavesurfer@lemmy.zip 2 points 6 days ago (1 children)

Well, it really depends on if you want somebody to trust or not. If you don't want to trust anybody except yourself, then you can just use Tofu and be good with it. The only reason I brought up using search engines as an index is just to give people a place to look.

If I want to visit CNBC and I've never visited them before, I could just go straight to CNBC and trust their certificate right away. Or, if I wanted to confirm that the CNBC certificate was likely valid, I could ask DuckDuckGo, Google, and Quant. And if they all agreed that they had the same certificate that I was getting, I'd be more likely to think that it's valid.

[–] marauding_gibberish142@lemmy.dbzer0.com 1 points 6 days ago (1 children)

This is actually a great idea. Is there an opensource implementation of it?

[–] shortwavesurfer@lemmy.zip 2 points 6 days ago (1 children)

Well, you can just generate your own SSL certificate on your machine, locally. I believe you can probably do it with OpenSSL. I've only done it with my Monero node, and they offer a binary, which will generate a certificate for you. I would just look up how to create a self-signed SSL certificate. My guess is it's just a few commands in the terminal.

[–] marauding_gibberish142@lemmy.dbzer0.com 2 points 6 days ago (1 children)

No, I meant the logic where the browser would prompt the user to review and verify the cert for a particular website without consulting a CA. I run some self-signed certs already but I'd love to implement this in my homelab.

[–] shortwavesurfer@lemmy.zip 1 points 6 days ago

Oh, that was an idea for a way to do it. Not anything that's been implemented, or at least not to my knowledge.