Skip to content

Comment on Automatic HTTPS Enforcement for New Executive Branch .gov Domainsparent

Comments

Sorry, I'm not going to continue arguing with you. It's clear you don't understand the scope of what you're proposing is happening.

I'm just saying you're making claims you cannot possibly verify. You say nobody is collecting your keys even though all you have is a lack of evidence either way. I also think you're probably, accidentally, right in this case. But only because I doubt you really have adversaries who care.

You're confusing being uninteresting with being safe. (Safety is numbers is irrelevant once you've been selected.)

Sorry, I'm not going to continue arguing with you.

Stop clicking Reply.

Strangely, many tech folks seem to have normalized some very wild fantasies about what the NSA does.

I'm using the NSA as an example of a foe of sufficient capability, not saying that this is what they do (to our own agencies at any rate.) Someone who can trojan hardware, suborn any given person, etc.

I was hoping to use a very advanced force as an example to show that things that may sound secure aren't if your attacker has a certain level of resources.

Fwiw, most pen-testers would aso be able to bypass any such casually enacted system too, but that's less obvious so I had hoped to avoid that argument by going with an extreme example.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.