While it is useful to rely on technological schemes for protection, it would be short-sighted to rely *only* on technological schemes for protection - knowledge and personal responsibility are the ultimate defenses.
Until the technological scheme is improved by the affected vendor(s) (evidence of which would be public disclosures of the breach and remedial measures undertaken), I have chosen to delete all Comodo Root certificates from my systems. People who try to protect their personal economic interests by hiding information that secures other people's economic interests, forget that the buyer always has choices. Thanks for the posting, Peter and Jacob. Arshad Noor On 03/22/2011 11:04 PM, Peter Gutmann wrote:
Interesting post by Jacob Appelbaum on the compromise of a trusted CA that was used to issue fraudulent certificates: https://blog.torproject.org/blog/detecting-certificate-authority-compromises-and-web-browser-collusion The discussion shows up (yet again) one of the (several) killer problems of CRL/OCSP-style blacklisting, since you can only blacklist certs that you know that a certificate vending machine has issued, there could be arbitrary numbers of further certs out there that can't be revoked because the vending machine doesn't know that it issued them.
_______________________________________________ cryptography mailing list [email protected] http://lists.randombit.net/mailman/listinfo/cryptography
