▲ | gruez 4 days ago | ||||||||||||||||||||||||||||||||||||||||||||||||||||
>And I would argue that MITMing communications is a lot hard for (non-nation state) attackers than compromising a host, so trust compromise is a questionable worry. By that logic, we don't really need certificates, just TOFU. | |||||||||||||||||||||||||||||||||||||||||||||||||||||
▲ | throw0101d 4 days ago | parent [-] | ||||||||||||||||||||||||||||||||||||||||||||||||||||
> By that logic, we don't really need certificates, just TOFU. It works fairly well for SSH, but that tends to be a more technical audience. But doing a "Always trust" or "Always accept" are valid options in many cases (often for internal apps). | |||||||||||||||||||||||||||||||||||||||||||||||||||||
|