[EMAIL PROTECTED] wrote:

> as discussed in the rest of this thread and the side thread
> http://www.garlic.com/~lynn/aepay10.htm#78 ssl certs
> http://www.garlic.com/~lynn/aepay10.htm#79 ssl certs
>
> is that the whole SSL certificate infrastructure is already based on domain
> name infrastructure ....

This is not quite correct. The DN in a X.509/PKI cert had nothing to do with
the DNS. It was the lack of foresight of some people that has made PKIX
vulnerable to yet another problem -- the DNS.

Also, may I recall that there is no "SSL certificate infrastructure". What we
have is a PK wanna-be I.  And, SSL is broken anyway. It does not prevent
server spoofing, its MSIE implementation allows easy MITM attacks
that can read all traffic in the clear, and there are additional 24 problems (dure
to PKI) that I have documented since 1997, which paper was downloaded more
than a million times and presented at the Balck Hat Conference in  '99. You can
search in google for a copy near you, using the query
"Overview of Certification Systems Gerck"

And, PKI certs are simply too big for wireless and also for everyday use --
this message would probably more than double in size if signed.

Cheers,
Ed Gerck


Reply via email to