<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" href="/styles/rss-style.xsl"?>

<rss version="2.0"
 xmlns:blogChannel="http://backend.userland.com/blogChannelModule"
>

<channel>
<title>teodesian.net</title>
<link>http://teodesian.net//posts/73e74d3f-13f4-11ec-bdd7-c2095a35cd32?format=xml</link>
<description>teodesian.net : /posts/73e74d3f-13f4-11ec-bdd7-c2095a35cd32</description>
<language>en</language>
<pubDate>2026-04-20T08:05:07</pubDate>
<lastBuildDate>2026-04-20T08:05:07</lastBuildDate>

<image>
<title>teodesian.net</title>
<url>/favicon.ico</url>
<link>http://teodesian.net</link>
<width>32</width>
<height>32</height>
<description>teodesian.net favicon</description>
</image>
<item>
<title>EV to lose the &#x22;happy bar&#x22; indication</title>
<link>http://teodesian.net/posts/73e74d3f-13f4-11ec-bdd7-c2095a35cd32</link>
<description><![CDATA[Good, as it's been a joke the entire time. The crypto's all the same regardless, and it's not like I know who and trust the guys at whatever CA issues them, so the argument that it is a "web of trust" is mostly hokum. This is further evidenced by years and years of mis-issuance. Only DNSSEC can square the circle of "this cert actually is the one for this website", but even then DNS is subject to being spoofed & thugged out by government or similarly empowered entities.
<br /><br />
Considering how easy it is to get a DV cert these days, the broswer vendors may as well just allow self-signed again.]]></description>
<author>teo</author>
<guid isPermaLink="true">http://teodesian.net/posts/73e74d3f-13f4-11ec-bdd7-c2095a35cd32</guid>
<pubDate>2019-08-13T06:42:33</pubDate>
<enclosure type="text/html" url="http://teodesian.net/posts/73e74d3f-13f4-11ec-bdd7-c2095a35cd32" />
</item>
<item>
<title>EV to lose the &#x22;happy bar&#x22; indication</title>
<link>http://teodesian.net/posts/1565678553</link>
<description><![CDATA[Good, as it's been a joke the entire time. The crypto's all the same regardless, and it's not like I know who and trust the guys at whatever CA issues them, so the argument that it is a "web of trust" is mostly hokum. This is further evidenced by years and years of mis-issuance. Only DNSSEC can square the circle of "this cert actually is the one for this website", but even then DNS is subject to being spoofed & thugged out by government or similarly empowered entities.
<br /><br />
Considering how easy it is to get a DV cert these days, the broswer vendors may as well just allow self-signed again.]]></description>
<author>teo</author>
<guid isPermaLink="true">http://teodesian.net/posts/1565678553</guid>
<pubDate>2019-08-13T06:42:33</pubDate>
<enclosure url="http://teodesian.net/posts/1565678553" type="text/html" />
</item>
</channel>
</rss>
