Re: [cryptography] PFS questions (was SSL *was* broken by design)

2011-10-05 Thread ianG
On 4/10/11 10:18 AM, Steven Bellovin wrote: Come on. This discussion has descended past whacko, which is where it went once the broken by design discussion started. Quite. I had to point someone at some of these threads today; when it came to this part, I alluded to black helicopters.

Re: [cryptography] PFS questions (was SSL *was* broken by design)

2011-10-05 Thread Marsh Ray
On 10/05/2011 07:57 AM, ianG wrote: This thread originated in a state-led attack on google and 4 CAs (minimum) with one bankruptcy, one state's government certificates being replaced, measured cert uses (MITMs?) in the thousands. Just for the record, the Fox-IT Interim Report September 5,

Re: [cryptography] PFS questions (was SSL *was* broken by design)

2011-10-05 Thread James A. Donald
On 2011-10-06 12:34 AM, Marsh Ray wrote: Just for the record, the Fox-IT Interim Report September 5, 2011 DigiNotar Certificate Authority breach 'Operation Black Tulip' https://bugzilla.mozilla.org/attachment.cgi?id=558368 states that: Around 300.000 unique requesting IPs to google.com have