Re: [therightkey] Basically, it's about keeping the CAs honest

Paul Lambert <paul@marvell.com> Thu, 16 February 2012 21:32 UTC

Return-Path: <paul@marvell.com>
X-Original-To: therightkey@ietfa.amsl.com
Delivered-To: therightkey@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id AEB1821E808E for <therightkey@ietfa.amsl.com>; Thu, 16 Feb 2012 13:32:15 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.435
X-Spam-Level:
X-Spam-Status: No, score=-6.435 tagged_above=-999 required=5 tests=[AWL=0.164, BAYES_00=-2.599, RCVD_IN_DNSWL_MED=-4]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id xVGjwNNTFP7l for <therightkey@ietfa.amsl.com>; Thu, 16 Feb 2012 13:32:11 -0800 (PST)
Received: from na3sys009aog101.obsmtp.com (na3sys009aog101.obsmtp.com [74.125.149.67]) by ietfa.amsl.com (Postfix) with ESMTP id F137A21E8052 for <therightkey@ietf.org>; Thu, 16 Feb 2012 13:32:09 -0800 (PST)
Received: from sc-owa02.marvell.com ([65.219.4.130]) (using TLSv1) by na3sys009aob101.postini.com ([74.125.148.12]) with SMTP ID DSNKTz1117q0Ahkxr62KHk485tAnAvbTa7JT@postini.com; Thu, 16 Feb 2012 13:32:11 PST
Received: from SC-vEXCH2.marvell.com ([10.93.76.134]) by sc-owa02.marvell.com ([10.93.76.22]) with mapi; Thu, 16 Feb 2012 13:29:01 -0800
From: Paul Lambert <paul@marvell.com>
To: Tom Ritter <tom@ritter.vg>, Phillip Hallam-Baker <hallam@gmail.com>
Date: Thu, 16 Feb 2012 13:29:00 -0800
Thread-Topic: [therightkey] Basically, it's about keeping the CAs honest
Thread-Index: Aczs4La/DFurP5cYTZW0SDigmZlLSQAEMuFQ
Message-ID: <7BAC95F5A7E67643AAFB2C31BEE662D01579DA1995@SC-VEXCH2.marvell.com>
References: <gym9r33x3m8ydl4xwbjezwJv4X.penango@mail.gmail.com> <201202160524.q1G5ON2p003570@fs4113.wdf.sap.corp> <CA+cU71n1HeQ3nK_FjM67dO8U7=HmDBG3q0_4cvH9CY6Y0_=9BQ@mail.gmail.com> <CAMm+LwiQdXo6bmYmtyR7aw1S=A889edFdSU5aAJVgN4ZMwNrFw@mail.gmail.com> <4F3D481E.40001@fifthhorseman.net> <CAMm+LwhrxnznFUTf_TJERjt0rNo+Offs2aUnKLPP2JBR8SYVSA@mail.gmail.com> <CA+cU71kvQ4b2QsowgtjfM6qG0UWAMG5jvPPZTtD9KgqA01DaiA@mail.gmail.com>
In-Reply-To: <CA+cU71kvQ4b2QsowgtjfM6qG0UWAMG5jvPPZTtD9KgqA01DaiA@mail.gmail.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
acceptlanguage: en-US
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
Cc: "therightkey@ietf.org" <therightkey@ietf.org>, Daniel Kahn Gillmor <dkg@fifthhorseman.net>
Subject: Re: [therightkey] Basically, it's about keeping the CAs honest
X-BeenThere: therightkey@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: <therightkey.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/therightkey>, <mailto:therightkey-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/therightkey>
List-Post: <mailto:therightkey@ietf.org>
List-Help: <mailto:therightkey-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/therightkey>, <mailto:therightkey-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 16 Feb 2012 21:32:15 -0000

>I'd also like to go on the record that I think a visual indicator to
>the user that shows a cert is valid only under local policy is a
>fantastic idea and I support it wholeheartedly.  Of course UI is hard,
>especially with this opaque a topic to an average user, but I still
>think giving it a shot is a good idea.

A similar usage of colors - with poor results:
http://www.usablesecurity.org/papers/jackson.pdf 

Is local policy more or less secure to the user?  I'd say more ...