[EMAIL PROTECTED] wrote:
> as discussed in the rest of this thread and the side thread > http://www.garlic.com/~lynn/aepay10.htm#78 ssl certs > http://www.garlic.com/~lynn/aepay10.htm#79 ssl certs > > is that the whole SSL certificate infrastructure is already based on domain > name infrastructure .... This is not quite correct. The DN in a X.509/PKI cert had nothing to do with the DNS. It was the lack of foresight of some people that has made PKIX vulnerable to yet another problem -- the DNS. Also, may I recall that there is no "SSL certificate infrastructure". What we have is a PK wanna-be I. And, SSL is broken anyway. It does not prevent server spoofing, its MSIE implementation allows easy MITM attacks that can read all traffic in the clear, and there are additional 24 problems (dure to PKI) that I have documented since 1997, which paper was downloaded more than a million times and presented at the Balck Hat Conference in '99. You can search in google for a copy near you, using the query "Overview of Certification Systems Gerck" And, PKI certs are simply too big for wireless and also for everyday use -- this message would probably more than double in size if signed. Cheers, Ed Gerck
