It would be simple today to abolish the use of CAs but it just a big cargo biz that makes money on nothing as usual based on peoples incompetence. For 99% of all sites today security would be handled better without CAs. People simply don't understand how it works.
All that was true until fairly recently. Today, you can get certificates for free and there’s more transparency than ever thanks to CT.
What would you suggest as an alternative? TOFU?
I could see that for local applications (e.g. making mDNS/.local and private IP certs TOFU capable by default would be amazing, and maybe even for some explicit hobbyist public TLDs?), but I don’t think I’d love it for my bank or email provider.
> It would be simple today to abolish the use of CAs […]
The main technical way I know of doing this would be by putting TLS public keys in DNS (DANE, RFC 6698), but then you have to make sure that DNS packets are not fiddled with, so you need to bring in DNSSEC.
That's a false concern, because the names the CAs are certifying are still DNS names. If your TLD reasssigns your DNS name out from under you, or even if your TLD starts returning false data on only selected queries, the CAs will be happy to issue a cert to the new holder.
It would be great to have a widely-recognizable pseudodomain out there where the names were key hashes. It would actually graft really easily into DNSSEC. The zone format doesn't have to change at all; you just declare that if the KSK hash matches the domain label under this specific TLD, you don't need to check upstream of that. Then you add a P2P protocol for getting the actual data, and start slowly pushing that protocol down the resolver tree to incrementally decentralize everything.
I would like to see some sources on your claim about it being Russian. It is incorporated in the US with most developers in Amsterdam.
After the invasion of Ukraine they stayed silent for a while but that was because they needed to allow there developers to get out of Russia. Many of them are Ukrainians including the CTO and founder. As soon as it was safe for there team they took a very firm stance against Russia with Ukrainian flags on the website and written statement from the team.
I am not aware of any Russian influence currently.
It was created at Yandex, the biggest techcorp in Russia, by Alexey Milovidov among others. He is still the CTO there. So I will stay away. There are many good alternatives to pick.
We’ve come at a time in which we fear exploring projects like Apache Doris because we fear that OSS might be used in malicious ways by state-backed actors.
There's quite a bit of research out there showing that application performance has a material impact on checkout conversion rate, so a single platform optimization potentially improves checkout for millions(?) of storefronts.
Google research from a decade ago that might as well been that their bot did not want to wait for pages to load. The performance difference between React native and a web wrapped in an app is pretty much zero today.
We booted react native like 10 years ago and there is not much a web does not solve. We even did solve it for the desktop users anyway even before. A simple app as Shopify with mostly static content should not be any problem to build as a web.
As I recall it. This was mostly a money scam that targeted private users with ads like "make sure to claim to your .name domain so no one else does it and use it to impersonate you". It was stupid from the beginning and never took off.
reply