Comment: Re:My question about Convergence (Score 1) 127
Convergence seems to solve the problem of a government (Iran) placing fake certs in front of their users and decrypting their GMail and FB SSL connections, and what have you. But what if the fake cert is placed much closer to the target website which is being spoofed?
That could be mitigated by having at least one notary running DNSSEC, but then you can't have a consensus, you have to have all notaries agree, and require the DNSSEC one to agree. This would work, but in that case, just use DNSSEC (Which I do
...Or some notaries could use the current CA system. The point is _trust agility_ and that you if you employ these certificate checks as an extra measure, you can not be in a worse situation than with the current CA system. In a nutshell: You don't have to trust CAs, you don't have to trust DNSSEC and you don't have to trust notaries that just compare certificates. But you can choose to trust them if they agree (and even if they don't).