On Wed, Mar 23, 2011 at 7:04 AM, Peter Gutmann <[email protected]> wrote: > Interesting post by Jacob Appelbaum on the compromise of a trusted CA that was > used to issue fraudulent certificates: > > https://blog.torproject.org/blog/detecting-certificate-authority-compromises-and-web-browser-collusion
Thanks Peter. This couldn't be more timely. The National Science Foundation is holding an invitational workshop on the subject 'Trust Anchors are Invulnerable' - this is the second in the Cyber Security Assumption Buster Workshop Series: http://www.nitrd.gov/fileupload/files/TrustAnchors_2011_NITRD_workshop_v2.pdf The participation fee is a one or two page position paper addressing the questions proposed in the call. The submission deadline expires today. Anyone willing to writeup something together? Proposed title: 'Tell me what you trust and I'll tell where is the flaw' or 'How your trust anchor might make your attacker more confident.' Regards, -- Alfonso De Gregorio BeeWise - Security Event Futures: http://beewise.org/ The first prediction market for forecasting security events and trends >From my blog: Layered Weak Links - The Ability to Refresh Attack Cost is Key to Mission Success, but Seldom Available: http://plaintext.crypto.lo.gy/ _______________________________________________ cryptography mailing list [email protected] http://lists.randombit.net/mailman/listinfo/cryptography
