This weekly roundup thread is intended for all culture war posts. 'Culture war' is vaguely defined, but it basically means controversial issues that fall along set tribal lines. Arguments over culture war issues generate a lot of heat and little light, and few deeply entrenched people ever change their minds. This thread is for voicing opinions and analyzing the state of the discussion while trying to optimize for light over heat.
Optimistically, we think that engaging with people you disagree with is worth your time, and so is being nice! Pessimistically, there are many dynamics that can lead discussions on Culture War topics to become unproductive. There's a human tendency to divide along tribal lines, praising your ingroup and vilifying your outgroup - and if you think you find it easy to criticize your ingroup, then it may be that your outgroup is not who you think it is. Extremists with opposing positions can feed off each other, highlighting each other's worst points to justify their own angry rhetoric, which becomes in turn a new example of bad behavior for the other side to highlight.
We would like to avoid these negative dynamics. Accordingly, we ask that you do not use this thread for waging the Culture War. Examples of waging the Culture War:
-
Shaming.
-
Attempting to 'build consensus' or enforce ideological conformity.
-
Making sweeping generalizations to vilify a group you dislike.
-
Recruiting for a cause.
-
Posting links that could be summarized as 'Boo outgroup!' Basically, if your content is 'Can you believe what Those People did this week?' then you should either refrain from posting, or do some very patient work to contextualize and/or steel-man the relevant viewpoint.
In general, you should argue to understand, not to win. This thread is not territory to be claimed by one group or another; indeed, the aim is to have many different viewpoints represented here. Thus, we also ask that you follow some guidelines:
-
Speak plainly. Avoid sarcasm and mockery. When disagreeing with someone, state your objections explicitly.
-
Be as precise and charitable as you can. Don't paraphrase unflatteringly.
-
Don't imply that someone said something they did not say, even if you think it follows from what they said.
-
Write like everyone is reading and you want them to be included in the discussion.
On an ad hoc basis, the mods will try to compile a list of the best posts/comments from the previous week, posted in Quality Contribution threads and archived at /r/TheThread. You may nominate a comment for this list by clicking on 'report' at the bottom of the post and typing 'Actually a quality contribution' as the report reason.

Jump in the discussion.
No email address required.
Notes -
Is pki the next part of the global internet censorship regime?
In a previous post, we discussed the takedown of a foreign website that violated texas laws. I argued that domain takedowns are unlikely to be used for global censorship. But these days https certificates are becoming nearly obligatory, and the system around them is much more haphazard.
As a sideshow on the iran situation, the pgsa dot ir website is trying to stay up in the face of the sanctions. The website originally had a letsencrypt certificate, but obviously the US was able to get that yanked. After a week, they managed to get their hands on a chinese certificate. But surprisingly, only a few days later, the certificate was revoked, making the https site unviewable on certain browsers. I'm not certain exactly why the chinese issuer revoked it, but it could likely be due to pressure from above.
Unlike the internet, Google, Apple, and Mozilla pretty much control almost every browser in the world. And for an issuer it seems that there are no rules when it comes to having your certificates accepted on those browsers, simply beg and kiss ass to each of them until they decide to let you in the club. This means that anywhere, having an https website happens at the whim of these 3 American companies, and each one pretty much has a veto over the process. It's no wonder that they all go to lengths to put up big warnings and gimp functionality on http websites.
Of course it remains to be seen whether or not this lever of censorship will be used in the future and for what purposes. Can an SF judge order Mozilla to start rejecting certain certificates? Not sure. Right now there's also the escape hatch of simply using http, but browser makers will continue to push more and more invasive warnings about it.
The PKI infrastructure for https was always half a scam, more a license to print money for whomever could convince the browsers to add their root key than anything. (Dear website owner who (had to) pay every year for your ssl certificate: check how long your browsers root certificates stay valid. Feel scammed yet?)
The fact that it is largely independent of DNS seems particularly silly. Certificates tied to hierarchical domain names would probably be an improvement. Everyone running a country code TLD could simply specify which certificates are valid for that particular TLD. Let DENIC (or German legislation) decide which CAs can validate .de certificates. Then it would seem reasonable to require devices with TLS-capable browsers sold in Germany to have these CAs and only these CAs enabled for .de. For bonus points, simply ship the TLS certificates over dnssec, so browsers only need to know the public keys of the root servers (while also adding non-Western root servers).
Similarly, Iran would have CAs for .ir. Yes, this means that they could MITM any .ir website, but I do not think that many dissident sites run under .ir in the first place. (The fix there would be a browser plugin which uploads any certificate chain it encounters. So any bad actor could be easily identified.)
--
Also, it is becoming increasingly clear that the US can not be trusted as a steward of the internet any more than it can be trusted as a steward of free trade or the international rule-based order.
Trump's little war really does not seem to go well. In the beginning, his actions could be described as "grand but foolish", like assassinating the ayatollah or dropping a lot of bombs on the IRGC.
Now, he has escalated to ... (check notes) ... threatening a trade war with China if it does not follow US sanctions?
And the next plan to stop Iran from blocking Hormuz is to use the US influence on the internet to make the Iranian Persian Gulf Strait Authority unable to have a website which is loaded by default browsers? Surely that will be enough to get an unconditional surrender.
And if Iran does not bow to this, one could apply further pressure by evicting the Iranian delegation to the United Nations, I am sure that this would be devastating to them and well worth any transient reputational damage to the US as the host of the UN.
More options
Context Copy link
On all of those you can add custom roots and chains. Now whether you would want to put Iranian government root just to visit their sites securely is up to you.
IIRC not all US government-issued certificates are recognized by the default on the listed browsers. At least, I've run into SSL warnings from them before that indicated as such in the past. The reverse you hope would be true too: important systems probably shouldn't need to trust foreign CAs for just any sites.
Also, I think Firefox on most platforms (Windows, most notably) trusts the OS's CA list: Microsoft probably has more sway than Mozilla. The one time I can think of this power was used, it was against Symantec for what seemed at the time (2018) quite reasonable reasons.
As I understand the documentation, it trusts root certs that have been added to the OS by an administrator or user but not those included by Microsoft or Apple.
More options
Context Copy link
More options
Context Copy link
More options
Context Copy link
Http is not ideal unless the website is purely static. Even then... Web3 is likely the solution. Domain ownership and https cert should be on a blockchain, not at the discretion of 4 hiveminds.
Maybe the web should be purely static again. Web 2.0 was a mistake.
I’m not exactly sure how you envision the blockchain helping, here.
There has to be a trusted cert. Just put it on the blockchain, same with domain ownership. When someone holds a domain on the blockchain they can issue a cert for it that lives on the blockchain too and is used for their https.
Blockchains provide low-trust secure public timestamping, which means they can confirm priority and therefore resolve double-spend disputes (which is how they enable cryptocurrency). The issue with certificates is whether the public key is correct in the first place, and blockchains don't provide any additional security beyond the key-signing process - fundamentally you can't trust that a public key is correct unless you trust the person who published it, or someone else who signed it.
If two certificates for the same person or entity with different public keys are published at roughly the same time, either both are valid (you can have multiple public keys) or one should explicitly revoke the other. There is no question of priority.
Shouldn't keys be self published? As in someone has a wallet, they can buy domain ownership on the blockchain, their wallet then publishes the correct key. It is verified by the fact that their wallet is the owner of the domain on the blockchain. Their wallet also sets the config.
Is what you want "the certificate shows this server verifiably is run by the owner of the domain (or an approved proxy)?" That's not all the current regime is doing: there is a nonzero amount of "and is an upright business interest" there that crypto has well-known issues with. How would you revoke or reject certs from malware hosts? Even if LetsEncrypt isn't checking site contents, the browser vendors are still doing so, functionally replicating the original centralized PKI complaints.
You are saying censorship is baked in to the system for safety reasons. The solution here is to make censorship opt-in instead of forced. Censorship companies can run a censorship server that I query if I'm so paranoid about malware websites having TLS certs. If you make it to where I have to obey the censorship authority no matter what, then they inevitably start exploiting their power to perform political censorship.
If you're that concerned about censorship, why use TLS at all? It makes sense if you're concerned about privacy -- assuming your counterparty's certs are actually secured -- but then you also want to make sure your counterparty is who they say they are so you don't leak messages to the wrong parties.
There is a very real privacy-censorship tradeoff here that is inherent in any indirect trust scheme: unless you're trading RSA keys out-of-band with your servers (not bad if you can), the PKI problem isn't really escapable. Web of trust never worked as an alternative. Any centralized solution there begets censorship.
More options
Context Copy link
More options
Context Copy link
More options
Context Copy link
More options
Context Copy link
More options
Context Copy link
More options
Context Copy link
More options
Context Copy link
Sure, why not. So if you connect to some website, your browser will simply fetch the latest blocks and compute which address currently owns that domain. After all, you would not want to trust any single third party (which could just decline requests for particular domains).
Keeping your phone synced with a blockchain seems doable, but will likely require a lot of storage and computation effort. Bad if you care about battery life.
It could be done by proxy. Just query another server that stores an up to date copy of it. Advanced users could roll their own by doing it on a home server and making their phone query that.
The problem with the proxy approach is that you then need to trust that proxy. Say I buy a new Pixel phone. Now, Google wants to sell these to normies, so "please give me the IP address of your trusted blockchain DNS/CA host" is not going to be part of the setup process. Instead, they would all point to the same central server offering DNS/CA services, and if the USG does not want them to resolve a certain website, it simply won't.
So the end result is not that different from the status quo: people who care enough to ask an LLM for help and nerds will be able to access Iranian sites, and everyone else won't.
More options
Context Copy link
More options
Context Copy link
More options
Context Copy link
More options
Context Copy link
More options
Context Copy link