> I think we would prefer this proposal, or something like it, over both
> the current, insecure state and one in which we’re forced to hack TLS
> on in an almost pointlessly insecure manner (though given the current
> and imminent state of browsers, we’re probably going to have to
> do that anyway...).

Did you give consideration to the suggestion above that developers could
simply be asked to accept a self-signed certificate presented by the device
upon connection? It seems like that would properly put the burden of
bypassing the existing PKI implementations upon the subset of users who
want to develop applications on the web that are distributed to devices
without installing any software.

If it works the way I'm claiming it does (Joel? :) And perhaps someone from
Mozilla can weigh in about their implementation...), it would seem to be a
relatively low burden for that subset of users to bear, and would entail no
change from status-quo for the rest of the web.


