<< Weekly Status Report, W34/2011 | The roads I take... | 47 >>

Weekly Status Report, W35/2011

Here's a short summary of SeaMonkey/Mozilla-related work I've done in week 35/2011 (August 28 - September 4, 2011):

The security discussions around the DigiNotar stuff took a lot of time to read this week, but they taught two lessons, I think: 1) The CA model has serious problems in its design as it needs us to trust that CAs do the right thing and are not broken into, and 2) as long as we need that CA model, any CA that wants to keep their business running needs to immediately and fully disclose to the major browser vendors (i.e. the keepers of the CA root stores) when something goes wrong - if they fail to do that, consequences quickly need to run toward their complete exclusion, like it was in this case.

Beitrag geschrieben von KaiRo und gepostet am 6. September 2011 14:40 | Tags: L10n, Mozilla, SeaMonkey, Status | 2 Kommentare | TrackBack

Kommentare

AutorBeitrag

KaiRo

Webmaster

zitieren
jmdesp:
I agree that it's easier said than done, and I don't have a solution. You're also right that it's in inherent flaw in the design of the whole model. And of course, we need to work with that model for the foreseeable future, but I'd be happy if someone would find a better model that doesn't have this problem.
07.09.2011 12:42

KaiRo

Webmaster

zitieren
I didn't come around to blogging, but there's another status update coming that sums up the silent time...
12.10.2011 23:53

Kommentar hinzufügen