funsec mailing list archives

Re: Public Policy and Consumer ISP Hygiene (was Comcast pop-ups)


From: Rich Kulawiec <rsk () gsp org>
Date: Tue, 13 Oct 2009 10:58:44 -0400

On Tue, Oct 13, 2009 at 09:27:46AM -0500, Dan White wrote:
Sure it would. The idea of an IPSEC enabled PKI is that you have end-to-end
security, with perhaps many untrusted networks in the middle. It means
two-way trust. 

Which is a nice idea, but increasingly meaningless in a world where there
are, at minimum, a hundred million already-compromised systems (I think 200M
is now a better low-end estimate), more every day, and every possible reason
to expect this problem to keep getting worse.

End-to-end security is worthless if one end is already enemy territory.

---Rsk
_______________________________________________
Fun and Misc security discussion for OT posts.
https://linuxbox.org/cgi-bin/mailman/listinfo/funsec
Note: funsec is a public and open mailing list.


Current thread: