[All Lists] [By Thread] [By Date] [Previous] [Next]


From: R. Halevi
Subject: What does certification prove?
Date: 11 Tishrei 5782


Consider the TLS certificate that secures this very mailing list.

The certificate proves that the server controls the domain. It does not prove the server is trustworthy. It does not prove the organization behind it is legitimate. It does not prove the content is true.

A user sees the padlock icon. The user concludes the site is safe. The certificate made no such claim.

—Dov Halevi


Thread:

[Previous] [Next]


DEP Discussion Archives
https://dep-specs.org/