Skip to content

Comment on Perfect Forward Secrecy can block the NSA, but almost no one uses itparent

Comments

That's what the people selling EV certs said. But EV certs have been a failure too, and they had a much louder UI.

And at least EV certs were backed by a concept that people could understand. It's unreasonable to expect people outside of tech to understand "forward secrecy".

It is at least possible that EV certs have seen limited uptake because people understand too much about them. After all, they are the same CA "sure you can trust us" scam that we've always had, except with more rent-seeking. Some users and/or site operators might have been influenced e.g. by EV certs' unsavory association with Comodo.

It is extremely unlikely that mass-market adoption of EV certificates has anything to do with the inside baseball of CA politics.

So strike my last sentence. EV certs are still more onerous for site operators in terms of price and process than "normal" certs. They don't offer a credible increase in security or decrease in liability for anyone. Those facts suffice to explain the paucity of their mass-market adoption.

Back then people didn't know the extent and depth of NSA's surveillance, so they weren't motivated to learn. The stakes are higher now.

In retrospect, the timing of Google introducing PFS is interesting. It's possible they introduced it because they either knew about or suspected the surveillance but either had no proof or were unable to talk about it. Of course, maybe they're just security conscious but it's interesting that Adam Langley so explicitly referred to the recording for later decryption scenario.

The USA has one of the least intrusive, least overbroad surveillance regimes in the world. Google introduced PFS because governments in places like India and Russia openly desire to intercept all communications.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.