Rocksolid Light

Welcome to RetroBBS

mail  files  register  newsreader  groups  login

Message-ID:  

If happiness is in your destiny, you need not be in a hurry. -- Chinese proverb


dovenet / Internet / Re: tailscale ..impressive

SubjectAuthor
* tailscale ..impressivefusion
`- tailscale ..impressivePhigan

1
Re: tailscale ..impressive

<647DA797.8799.dove-int@vert.synchro.net>

  copy mid

https://www.rocksolidbbs.com/dovenet/article-flat.php?id=57&group=DOVE-Net.Internet#57

  copy link   Newsgroups: DOVE-Net.Internet
From: fusion@VERT/CFBBS (fusion)
To: Phigan
Subject: Re: tailscale ..impressive
Message-ID: <647DA797.8799.dove-int@vert.synchro.net>
Date: Mon, 5 Jun 2023 05:14:00 +0000
X-Comment-To: Phigan
Path: rocksolidbbs.com!not-for-mail
Newsgroups: DOVE-Net.Internet
X-FTN-PID: Synchronet 3.20a-Linux master/90c924552 Jun 4 2023 GCC 12.2.0
X-FTN-CHRS: ASCII 1
WhenImported: 20230605021503-0700 c1e0
WhenExported: 20230605081433-0700 c1e0
ExportedFrom: VERT dove-int 8799
Content-Type: text/plain; charset=US-ASCII
Content-Transfer-Encoding: 8bit
 by: fusion - Mon, 5 Jun 2023 05:14 UTC

On 04 Jun 2023, Phigan said the following...
Ph> systems and browsers, the ones we trust. It's technically possible for
Ph> any of them to have master keys to the certificates they generate and
Ph> sign, but as the response in the link says, it's highly unlikely they
Ph> would go using those willy nilly.

no, that is not the case at all.

you send a CSR and the public key to the CA. that's it. there is no "master key". the CA's only purpose and capability is to validate the owner of a public key. they are incapable of decrypting anything.

now, lets say the kitchensync.net bbs has a certificate/public/private key they use. i can encrypt stuff all day long with the public key (in the
certificate) and nobody but that bbs would ever be able to see it. remember the CA doesn't have the private key.

now, if a shitty CA decides to sign a certificate for kitchensync.net with a different public key, that's an entirely different thing. since suddenly someone else can pretend to be them, and they have a separate private key that can decrypt data encrypted with the fake certificate. but in no way does this mean that the real certificate or private key are no longer secure. you
can't decrypt stuff from the original with the new ones.

--- Mystic BBS v1.12 A47 2021/12/25 (Windows/32)
* Origin: cold fusion - cfbbs.net - grand rapids, mi

Re: tailscale ..impressive

<647E273A.326.dove-internet@tacopronto.bbs.io>

  copy mid

https://www.rocksolidbbs.com/dovenet/article-flat.php?id=60&group=DOVE-Net.Internet#60

  copy link   Newsgroups: DOVE-Net.Internet
From: phigan@VERT/TACOPRON (Phigan)
To: fusion
Subject: Re: tailscale ..impressive
Message-ID: <647E273A.326.dove-internet@tacopronto.bbs.io>
Date: Mon, 5 Jun 2023 11:19:38 -0700
X-Comment-To: fusion
Path: rocksolidbbs.com!not-for-mail
Organization: Taco Pronto
Newsgroups: DOVE-Net.Internet
In-Reply-To: <647DA797.8799.dove-int@vert.synchro.net>
References: <647DA797.8799.dove-int@vert.synchro.net>
X-FTN-PID: Synchronet 3.19c-Linux / Jun 26 2022 GCC 9.4.0
X-FTN-CHRS: CP437 2
WhenImported: 20230605112710-0700 c1e0
WhenExported: 20230605201429-0700 c1e0
ExportedFrom: VERT dove-int 8802
WhenImported: 20230605111938-0700 41a4
WhenExported: 20230605112706-0700 41a4
ExportedFrom: TACOPRON dove-internet 326
Content-Type: text/plain; charset=IBM437
Content-Transfer-Encoding: 8bit
 by: Phigan - Mon, 5 Jun 2023 18:19 UTC

Re: Re: tailscale ..impressive
By: fusion to Phigan on Mon Jun 05 2023 05:14 am

> you send a CSR and the public key to the CA. that's it. there is no "master
> key". the CA's only purpose and capability is to validate the owner of a
> public key. they are incapable of decrypting anything.

That's when you're the one generating the cert request. What if some application or service is doing it for you? My point is more for messaging and other communication apps that tout "end to end encryption" vs SSL used for HTTPS.

---
■ Synchronet ■ TIRED of waiting 2 hours for a taco? GO TO TACOPRONTO.bbs.io

1
server_pubkey.txt

rocksolid light 0.9.8
clearnet tor