You know who else sounds like LLM from time to time? ESL - English as a Second Language. People learn English from books, and get introduced to phrases through reading or interacting with others within the same community. So, it sounds like you're using the LLM argument as a way to diminish their voices as well.
As an ESL person who has spoken English as their main language for two decades now I find this very interesting. The vast majority of my English has been spoken with my wife who used to be a marketing VP or in a professional context. Sometimes people complain about the ways politicians or corporate executives talk and I don't get it and to me it sounds totally normal because that's what I'm used to. Makes you wonder how ESL speakers will sound more and more like LLMs because that's a large part of their exposure.
It's only correct if "your right" is used as in "his right", "her right", "their right". Usually what they mean is "you are right", ergo "you're right", and they are just not educated enough to know how it's spelt.
I always saw it as a trust-chain and think that anyone is welcomed to create a root certificate and distribute it to whomever trusts them. Most simple services may not need TLS, but with the ISPs eavesdropping on our communication, a form of secure communication is required and the currently best solution we have requires a trust-chain to be built.
It is such a great improvement that ISPs cannot eavesdrop us anymore... only for everyone to terminate TLS at cloudflare so they (and thus US government) can now eavesdrop everyone.
Ultimately, I find it likely that TLS will become a tool to prevent users from accessing foreign content (browsers stubbornly refusing to show untrusted sites in the name of security, slowly getting there), more than a tool to prevent eavesdropping on users secrets.
If you have a service that shares information between people all over the world, a few big companies and one government is for most cases an improvement over all the involved ISPs and all of their respective governments.
>> 99.99999999999999% of internet users have no idea what root CAs even are
that would be like *checks math* less than a human aware of root CA? Can't be right.
anyway, people living in russia are statistically more aware. There was a campaign after new root CA was issued. It was on a news, on the official channels, in the mail and on the posters. A lot of government sites begged to install them whenever you visited.
I trust governments much less that a conglomerate of competing corporations.
With all the problems with Web PKI, at least the bad actors are getting distrusted, and this provides a very strong enforcement on the rest. And Certificate Transparency makes sure the mis-issuance would be caught. It is not perfect by any means, but things are getting better.
With DANE (or other country-issued certificates), every government will absolutely double-issue certificates to police, secret service and friends of goverment, and no one will have any recourse. (In the past I'd say that only countries like Russia would do it.. but with today's climate, I am sure both US and many European countries will do that too)
Companies have run some absolutely outstanding PR then.
I have never worked in any company where I explicitly trust the CEO to always do the right thing in every situation.
There is usually no governance board, or review system to inquire about public harm: those things are usually external and fought against as they are regulatory burden.
So, in practice what tends to happen is that someone in the company just does stuff. Since humans aren't perfect this "doing stuff" is not always super enjoyable. If it's the CEO who "does stuff" then you're cooked because nobody except the board of directors can say anything meaningful: you gotta hope that the media wants to put pressure on.
Our elected officials on the other hand, are supposed to represent us, and thus media pressure is a lot stronger; issues that affect many people are meant to be properly reflected, and their decisions are open by default.
I'm not really in favor of DANE, because DNSSEC is such a mess ... but.
Certificate transparency is nice. Browsers could require it for DANE certificates, just like they require it for current Web PKI certificates.
The people controlling the TLD of interesting can exert control over the domain of interest in order to issue a DANE certificate. But they can also exert control over the domain of interest in order to request a domain control certificate, so widespread use of DANE wouldn't add any new adversaries. If DNSSEC wasn't a mess, and DANE replaced WebPKI, we would eliminate the risk from CAs without adding a new risk --- TLDs (and the DNS root) are existing risks.
And if they don't, DNS is already a database. You could just query domains to check their certificates. People running recursive DNS servers could double-check certificates.
CT seems useless for DANE because the cert is self signed, so anyone can just flood the CT with self signed certs for your website. It's useful with WebPKI because only certs signed by a CA go in CT and it's a big deal if one is mis-issued. Anyone can mis-issue a self-signed cert at home for fun.
You'd have to do something like pre-publish in DNS, submit to CT which verifies that it's in DNS before logging. And the CT could rate limit on domain name or something to reduce abuse.
> every government will absolutely double-issue certificates to police, secret service and friends of goverment, and no one will have any recourse.
Countries already have CA that issue certificates with more legal force than a handwritten signature. I can open a bank account, pay my taxes and sign up to all government services. But I can't use them for a webpage.
> With DANE (or other country-issued certificates)
DANE isn't a country-issued certificate. It's a scheme where you store your public keys on DNS records. Of course, now we have the issue that DNSSEC (signed DNS records) isn't widespread and the whole issue with DNS registries.
DANE is entirely dependent on DNSSEC, and DNSSEC is, by design, under the government control, with all the bureaucratic mess and mistakes this implies.
This would be pretty terrible if anyone actually cared about DNSSEC, but luckily for us, no one cares.. So let's keep things this way.
Domain registries can already get a certificate for your domain by changing the address to their own server temporarily and then doing ACME with LE. So no new vector is introduced by directly putting the cert in DNS.
> I trust governments much less that a conglomerate of competing corporations
Let's not create a world wide PKI based on a political ideology.
> country-issued certificates [...] every government will absolutely double-issue certificates
This is such a strange argument. If you register a .ru domain, do you really think you are safe should the Russian intelligence services ask for a valid certificate? Controlling the actual domain, they could issue ask many domain validated certificates as they wish.
The problem with our current SSL PKI, as so very many people have pointed out over the years, is that any CA is allowed to issue valid certificates for any domain name. There have been proposals to use X.509 extensions to remedy this, but they have seen lesser real world usage than the various certificate revocation schemes, which is very close to zero already.
If there was no way for a Russian CA to issue certificates for .us domains, real world security would improve. A lot. And the other way around, of course.
Feel free to s/Russian/Chinese/ in the above argument or whatever tickles your geopolitical fancies. The argument still stands.
Domain registries decide who owns what domain. That is their literal role. You would think that asserting this ownership cryptographically would be a no-brainer in 2026. Yet we have this discussion over and over again. There are many people whose income quite literally depend on the status quo of our global SSL PKI, which coincidentally also offers no end of possibilities for the various intelligence services around the world.
The next time someone tries to scare you with that governments or intelligence services control DNS and therefore it would be crazy to limit issuance of certificates to them, take a look where they have contracts.
> The problem with our current SSL PKI, as so very many people have pointed out over the years, is that any CA is allowed to issue valid certificates for any domain name. There have been proposals to use X.509 extensions to remedy this, but they have seen lesser real world usage than the various certificate revocation schemes, which is very close to zero already.
Some of the browser root programs include (or have included) restrictions on what tlds a CA is allowed to sign. I think for some of the iffier CAs that nonetheless had a huge marketshare in their country of origin.
No need for the CA itself to include it in their root certificate.
It would be handy if the name restrictions actually worked though. Then you could probably get a CA to sign an intermediate CA authorized only to issue certs for your domain(s). There are some CAs that will do that already where they provide an HSM with the intermediate CA's key that will only sign certs for authorized domains, but the CA cert does not encode the constraint and this is permitted by the ca/b agreement. It just seems like it'd be nicer if it just worked.
It's not that high of a requirement. The sub-CA is allowed to self audit. But the original CA does have to check a percentage of certificates issued by the sub-CA.
So that's not going to be free. But it might be possible to do it if you were big enough to pay for it. I have dreams of having my private CA also signed off on by webpki so apps and browsers could use the same servers without having to include webpki in my apps.
I also started going down this rabbit hole when I wanted my homelab to just work in any device, and for advanced use cases Let's Encrypt isn't enough. I tried long and hard to get a sub-CA certificate, but apparently that's in the realm of «if you need to ask, you can't afford it».
If each country could only sign its own domains it would make sense. If the US could only tamper with .us domains the system could be trusted in general. After all, that's no worse than what they already do by coming to your house and putting a gun to your head.
Yeah, that's why most countries in EU, as well as US, are in a huge dissarray, politicians have all time low approvals, people vote for something and get the opposite, and the economy and social climate turned to shit...
I guess one doing well enough can be oblivious to all this...
Maybe, but then can only do it once. Then they get caught, and their CA is distrusted. See Diginotar [0] for example.
And things only gotten better since - we now have CT logs, and browsers require them, so any mis-issuance can be detected automatically, by any interested third party.
If we go to DANE, we lose this all. "Oops, our CT uploader process failed, we will fix Real Soon(tm) we promise" - and what are browsers going to do? Distrust the entire country?
Side note: “DigiNotar BV was a Dutch certificate authority from 1998 to 2011. It was acquired in January 2011 by VASCO and subsequently declared bankrupt in September of the same year” [1].
I didn’t realize the slapped their face on the pavement right after being acquired.
Apparently the cost of TLS these days is to subject yourself to whatever laws that countries of "free" TLS want to impose on you. That isn't very cheap.
I'd also love TOFU for TLS, at least on .local TLDs, but for publicly hosted websites, I've come around to the idea that maybe encryption without authentication would not help that much these days.
As for who does that authentication: Given all the suggestions in the sibling threads, I really don't think we're in a situation where there's a single entity gatekeeping access by any means.
In theory there is no difference between theory and practice, but in practice there is. Well, it gets complicated quickly when a wide range of users involved.
And YouTube recently (and silently) started approving multiple in-add ads for videos longer than 20 minutes. They destroyed the long-form content creators with their shorts push, and now it looks like they're trying to recover a little.
Just curious, what do you do with the increasing number of companies that use push notifications as a form of advertising venue, and how do you differentiate the security warning notification from your camera app from their special weekly annual sale notification?
The marginal cost of each notification is so low that companies simply spam users nonstop, and their A/B tests shows that the revenue is increasing. What's being lost though is that we're getting more and more agitated with these brands and their uncapped malicious behaviors. This is also true with their UI and UX as well, they keep adding banners with incredibly small close buttons, because someone will continue with the shopping after accidently missing the tiny button, and that's an added sale, who cares about 99% of users who are fuming with dissatisfaction, what are they going to throw away their $200-300 smart home device because companies abuse them?
On my Android, I aggressively mute or uninstall any apps that send push advertisements. I haven't seen one in more than 6 months now. If they think they need to advertise to me, I think I need to do without them.
If you read the thread the guy does own up to his actions. He actually sounds like a nice guy who admits he made a mistake. He seems more interested in preventing this kind of thing from being possible than he is interested in dodging blame.
Back in early days of personal computers, the instructor told us that a computer just does what you tell tell it to do, though not always what you thought, and making a mistake thousands of times a second hurts a lot.
If the agent didn't have delete permissions, or was sandboxed dying other way from your production database, that would handle it. So not running it that way is a decision someone made
Just in case this isn't hyperbole, no. It means an LLM should not be given that much privilege and that you are responsible for reviewing the tool's output and approving its actions.
Please be cognizant of fake plugins. They replicate entire plugins including the readme files and link to the original repos, but the code itself is different.
To be honest, in an emergency, this can easily create the perfect storm.
[0] https://www.federalregister.gov/documents/2026/07/27/2026-15...
reply