<-- back to the mailing list

Updated recommendations regarding TOFU & TLS

Petite Abeille petite.abeille at gmail.com

Fri Mar 5 12:27:01 GMT 2021

- - - - - - - - - - - - - - - - - - - 
On Mar 5, 2021, at 13:13, Philip Linde <linde.philip at gmail.com> wrote:
In my client, the user gets a choice whenever they encounter a new
certificate.

"Warning fatigue has pushed many messaging applications to remove blocking warnings to prevent users from reverting to less secure applications that do not feature end-to-end encryption in the first place."

https://en.wikipedia.org/wiki/Trust_on_first_use#Model_strengths_and_weaknesseshttps://en.wikipedia.org/wiki/Alarm_fatigue

This doesn't scale. Could as well accept everything. Or ignore everything. Same effect.

±0¢