While it is useful to rely on technological schemes for protection,
it would be short-sighted to rely *only* on technological schemes for
protection - knowledge and personal responsibility are the ultimate
defenses.

Until the technological scheme is improved by the affected vendor(s)
(evidence of which would be public disclosures of the breach and
remedial measures undertaken), I have chosen to delete all Comodo Root
certificates from my systems.

People who try to protect their personal economic interests by hiding
information that secures other people's economic interests, forget
that the buyer always has choices.

Thanks for the posting, Peter and Jacob.

Arshad Noor

On 03/22/2011 11:04 PM, Peter Gutmann wrote:
Interesting post by Jacob Appelbaum on the compromise of a trusted CA that was
used to issue fraudulent certificates:

https://blog.torproject.org/blog/detecting-certificate-authority-compromises-and-web-browser-collusion

The discussion shows up (yet again) one of the (several) killer problems of
CRL/OCSP-style blacklisting, since you can only blacklist certs that you know
that a certificate vending machine has issued, there could be arbitrary
numbers of further certs out there that can't be revoked because the vending
machine doesn't know that it issued them.

_______________________________________________
cryptography mailing list
[email protected]
http://lists.randombit.net/mailman/listinfo/cryptography

Reply via email to