Forgot your password?
typodupeerror
Security

Submission + - Disclosure: No-check SSL Certificates... (startcom.org) 4

StartCom writes: "In a previous article I reported about Man-In-The-Middle (MITM) attacks and if they really happen. Unfortunately it does happen as some testimonials confirm. Now it's even easier because in the attack described previously, untrusted certificates from an unknown issuer were used. Want to make the attack perfect with no error and fully trusted certificate? No problem, just head over to one of Comodo's resellers.

And here the disclosure: In order to confirm for yourself, edit the hosts file at your computer and add the following entry:"

This discussion was created for logged-in users only, but now has been archived. No new comments can be posted.

Disclosure: No-check SSL Certificates...

Comments Filter:
  • The CA system supported by modern browsers is fundamentally broken. The people being protected (end-users) are not the people buying the service (site owners). The people providing the service (CAs) can't individually protect anyone, because any other CA with poorer verification practices can make useless the service provided by the first CA.

    A notary system is better... the end-user pays for access to a notary system (or it comes with their browser, or they can use a free/p2p/etc one). They ask the notary w

    • According to the work done over at Mozilla, this shouldn't happen. The Mozilla CA Policy [mozilla.org] clearly requires domain control validation. Being myself part of the team which reviews CAs, I must say that there is a failure. It's unfortunate, because domain validated certificates do have a value and are excellent for protecting low-value sites like blogs, portals, webmail etc. But the practice disclosed in the article is certainly not going to work!
      • According to the work done over at Mozilla, this shouldn't happen.

        Yes, but that requires active enforcement against the economic incentives inherent in the system, which makes it fragile and IMO unreliable.

        • Some CAs [startssl.com] proved that verification can be done correctly for the right price. The others must go if greed compromises our security.

No line available at 300 baud.

Working...