moxie0 / Convergence

An agile, distributed, and secure alternative to the Certificate Authority system.
http://convergence.io
621 stars 108 forks source link

If convergence becomes mainstream, authorities can enforce MITM and disable secure connections altogether #157

Closed naiemk closed 12 years ago

naiemk commented 12 years ago

The massive problem I see with the convergence is that if it becomes mainstream, authorities, or corporates can selectively block notaries and force users to use their private notaries.

For example Iranian government can build a few national notaries and block all other notaries. Then the prospect of secure connection on internet becomes void in Iran altogether. Also what if MITM redirects all the requests to notaries to a fake notary?

Has this issue been thought of when designing convergence?

moxie0 commented 12 years ago

Requests can't be redirected to fake notaries, because those connections are authenticated using certificates pre-shared in the notary bundles. The censorship problem is of course an issue (as all censorship questions are), but ultimately beyond the scope of Convergence.