Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Some combination of distributed notaries, warning for unusual certificate conditions (e.g. certs changing when they have lots of time until expiration -- Dear Google, please stop doing that), and other ideas.

Convergence http://convergence.io/ (notary)

Perspectives http://perspectives-project.org/ (notary)

CertPatrol http://patrol.psyced.org/ (cert checking)

TACK http://tack.io/ (only one cert per organizational group would need signing or notarizing)



When given the option to choose who to trust, the vast majority of users will stay with the defaults, which are chosen by Google, Microsoft, and Mozilla. That's not fundamentally different from what's currently in place.

Tack is much more interesting. I'm too sleepy to fully understand the proposal, but what I've gathered so far looks promising.


Note that many of these are only usable for SSL.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: