6 ms·
The argument I have in favour of not requiring encryption is best summarised by what you have outlined. It would require a massive industry shift towards no obv
by jackweirdy 3y ago
The argument I have in favour of not requiring encryption is best summarised by what you have outlined. It would require a massive industry shift towards no obvious solution with no backwards compatibility that doesn't solve anything
Until I hear a convincing story of how I will do the usual lan tasks of
- connect to my router to fiddle with settings
- see the management interface on my printer
- join my parents network and do things for them without having to explicitly trust a CA
- And most importantly, see consumers who don't understand any of those things be able to do these things all out of the box
I can't see how it is a viable expectation
I totally love encryption. It's great. But seriously: what domain will I visit to fix my pppoe settings. Who's going to control that domain, and who's going to renew the certs for it. Because if the answer we will expect consumers and SMEs to trust a certificate authority created by a factory with its own crappy security practices, I'm not sure how that's an improvement
Otherwise we are breaking things to "fix" something that doesn't "fix" anything. if someone is MITMing my lan, it doesn't matter whether my router is TLS or not. it's compromised