[FD] end of useable crypto in browsers?

2016-04-09 Thread Árpád Magosányi
Hi, This is not a security vulnerability in itself, "just" a trend undermining the trust architecture of the whole internet :) I think it is very important, and wonder why I don't see any discussion of it. If this is not the right forum to discuss it, please direct me to the right place. The pro

Re: [FD] end of useable crypto in browsers?

2016-04-14 Thread Árpád Magosányi
ated discussion: > https://groups.google.com/forum/#!msg/mozilla.dev.platform/pAUG2VQ6xfQ/FKX63BwOIwAJ > . > Thank you for the pointer. It is sad to see how highly intelligent people fail to see the harm they cause. > Greetings, > Sebastian > > Am 2016-04-09 11:34, schrieb Árpád Mago

Re: [FD] new pen-test tool!

2014-07-07 Thread Árpád Magosányi
This looks like a valuable tool. But I would suggest to rethink some of the question of trust metrics, most importantly the first one. Size of the vendor have nothing to do with the level of trust you should have in it. If you have ever worked in a shop which is not at the bottom of the food chain

Re: [FD] SSH host key fingerprint - through HTTPS

2014-09-03 Thread Árpád Magosányi
Hi, (Is it within the list charter to discuss theoretical background?) On 09/01/2014 08:48 PM, maxigas wrote: > Excellent point and thanks for the tool! Indeed, fingerprint > verification is the absolute weak point of SSH. This is about trust relationship model. And the end-to-end trust relati