Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The irony here is, if you want "web of trust", you already have it; just remove all the certs from your browser and trust sites selectively.


Where's the "web" in that? Web of Trust is supposed to be a system where users 'tell' each other what they trust, forming a 'web' of trust links.


So when the certificate error comes up, ask your friends whether they trust it. You are talking about a web application that is almost "hello world" in Django or Rails.


So, build it. Then make it secure enough that any schmuck won't be able to hack it and serve fake 'trusts'. Then decentralize it so that governments like Iran's can't MITM it. Then solve the problem of having a single organization deploying thousands of fake nodes and poisoning the data.

After you've done that, yes, it'll exist.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: