Long-lived fission product FNRs can reduce the total radiotoxicity of nuclear waste, and its lifetime. With fast neutrons, the ratio between splitting and the capture of neutrons by plutonium or minor actinides is often larger than when the neutrons are slower, at thermal or near-thermal "epithermal" speeds. The transmuted even-numbered actinides e.

While organizations which control DNS and CA have likely reduced risk to trivial levels under most threat models, users and developers subjugated to other's DNS and a public CA hierarchy are exposed to non-trivial amounts of risk.

In fact, history has shown those relying on outside services have suffered chronic breaches in their secure channels. The pandemic abuse of trust has resulted in users, developers and applications making security related decisions on untrusted input.

The situation is somewhat of a paradox: Relying on untrusted input for security related decisions is not only bad karma, it violates a number of secure coding principals see, for example, OWASP's Injection Theory and Data Validation.

Pinning effectively removes the "conference of trust". An application which pins a certificate or public key no longer needs to depend on others - such as DNS or CAs - when making security decisions relating to a peer's identity.

SSH had it right the entire time, and the rest of the world is beginning to realize the virtues of directly identifying a host or service by its public key. Others who actively engage in pinning include Google and its browser Chrome.

Chrome was successful in detecting the DigiNotar compromise which uncovered suspected interception by the Iranian government on its citizens. Users, developers, and applications expect end-to-end security on their secure channels, but some secure channels are not meeting the expectation.

Examples of past failures are listed on the discussion tab for this article. This cheat sheet does not attempt to catalogue the failures in the industry, investigate the design flaws in the scaffolding, justify the lack of accountability or liability with the providers, explain the race to the bottom in services, or demystify the collusion between, for example, Browsers and CAs.

Patient 0 The original problem was the Key Distribution Problem. Insecure communications can be transformed into a secure communication problem with encryption.

Encrypted communications can be transformed into an identity problem with signatures. The identity problem terminates at the key distribution problem. They are the same problem.

The Cures There are three cures for the key distribution problem. First is to have first hand knowledge of your partner or peer i. This could be solved with SneakerNet. Unfortunately, SneakerNet does not scale and cannot be used to solve the key distribution problem.

The second is to rely on others, and it has two variants: Web of Trust and Hierarchy of Trust solve the key distribution problem in a sterile environment.

However, Web of Trust and Hierarchy of Trust each requires us to rely on others - or confer trust. In practice, trusting others is showing to be problematic.

