• 3 Posts
  • 1.09K Comments
Joined 6 months ago
cake
Cake day: January 3rd, 2024

help-circle






  • I would love to see the certificate authority model become less and less important.

    “Can you write a small check to an organization we are all pretty sure isn’t outright malicious?”

    Is a surprisingly good pragmatic protection against malicious SSL certificates, I will admit.

    But there’s significant flaws with the approach - notably power dynamics and creation of large scary targets for bad actors.

    I would love to see CA acceptance move from PASS/FAIL to a dynamic risk score, that is based on my own browsing behavior (calculated solely within my browser).

    If I spend 90% of my time browsing domains at example(dot)mycorporation(dot)com, there’s a great chance that anything new signed by the same authorities can be automatically trusted.

    It would still puts a lot of power in the hands of Amazon and Google, but would reduce that power in scale to the amount of services they’re actually providing to each user.








  • I’ll take “Organizations that made it to the top by doing something different, only to fall under leadership that doesn’t understand what made them successful and descend into ruins” for 200, Alex.

    Seriously, Jeopardy team - this is a rich category:

    • Netflix advertisements.
    • Zoom mandates staff return to offices.
    • Microsoft forgets what the “P” in “PC” stands for.
    • Toys R Us implements a shitty holiday gift returns policy.
    • Sears decides to sacrifice reputation for quarterly stock price gains.
    • Walgreens decides bottom-of-the-barrel incompetent pharmacists can uphold their “get it all done in one visit” secret sauce.
    • Radio Shack decides that once-every-two-years cellphone contract sales are the future for holding passionate electronics hobbyists’ loyalty.