there are integrity and vulnerability issues with the domain name
infrastructure

these integrity and vulnerability issues can result in various kinds of
"take-over" exploits.

the SSL domain name certificates are designed to detect ip-address
take-over exploits (not prevent them)  ... and do nothing to detect other
kinds of take-over exploits.

not detecting an exploit can lead to fraudulent transactions resulting in a
financial impact

detecting an exploit will effectively degenerate to a denial of service
exploit

integrity and vulnerability issues with the domain name infrastructure can
result in various kinds of denial of service exploits

denail of service exploits of the domain name infrastructure can result in
significant financial and economic impact, possibly on par with fraudulent
transactions.

just detecting an exploit and changing it from a fraudulent transaction
exploit to denial of service exploit would still represent a signficant
financial and economic impact

it is possible to take a baby step for real-time distribution of public
keys by the domain name infrastructure .... compared to the current
infrastructure

this baby step can compensate for existing domain name infrastructure
integrity issues by having the public key signed (as opposed to
distributing naked public keys)

the current SSL domain name operation is a certificate manufactoring
infrastructure w/o the certificate management characteristics necessary for
a PKI

the baby step distribution of real time public keys can provide effectively
the characteristic of management of public keys ... by deciding whether or
not to distribute the public key

the baby step is consistent with the certification authority business
proposal for addressing domain name take-over exploits (registering public
keys with the registering of the domain name).

the baby step doesn't address the elimination of denial of service exploits
(any more than the current SSL domain name certificates do).

with the baby step there can still be denial of service attacks on the
domain name infrastructure

the baby step of adding public key distribution to the domain name
infrastructure provides public key management capability significantly more
efficiently than either distributing CRLs to every potential client in the
world and/or having clients execute OCSP transaction.

the baby step is consistent with some future real time distribution of
"naked" public keys (w/o the signing envelope) at some future time when the
integrity and vulnerability issues of the domain name infrastructure have
been sufficiently addressed. there are significant financial and economic
justification for addressing these integrity and vulnerability issues just
based on the impact of denial of service exploits.

neither the existing ssl domain name certificate infrastructure nor the
baby step prevent ip-address take-over exploits and both just turn an
ip-address take-over exploit into a denial of service exploit.

neither the existing ssl domain name certificate infrastructure nor the
baby step prevent denial of service exploits

the baby step with real time distribution of public keys (whether enveloped
with signature for additional integrity or "naked") is consistent with the
certification authority business proposal for improving the integrity of
the domain name infrastructure by addressing domain name take over exploits
by registering public keys in the domain name database entry.


Reply via email to