3 ms·
SSL is completely and utterly useless without CAs. If there's no way to verify and trust that a given certificate belongs to the website it is being used on, an
by storborg 17y ago
SSL is completely and utterly useless without CAs. If there's no way to verify and trust that a given certificate belongs to the website it is being used on, any would-be-man-in-the-middle can just grab a random certificate and use it to completely eliminate all of the security that SSL provides.
- nailer 17y agoSure, but CAs are useless unless they actually verify the identity of the people they're giving certificates to. Verisign is the largest CA in the world and gave a certificate to a guy asking for a Microsoft certificate, without ever challenging him to prove his identity. Seeing as a the signature in a digital certificate is legally binding in most countries, there's no reason for Verisign to not be prosecuted for signing something saying they verify or trust the identity of the random gent when it's quite clear they did no verification and have nothing to base their trust upon. Yet I doubt they'll ever be prosecuted for it.
- nickf 17y agoThey did, yes. It was a code-signing certificate, and it was a relatively long time ago. You'd be hard pressed to do that again. Mistakes happen and always will - lessons were learned, procedures tightened. Nowadays getting, say, an EV certificate mis-issued would be hard. Not impossible as of course documents can be faked, people social-engineered - but it's definitely not as simple as just asking for a certificate anymore. Also - most CAs have insurance policies that can be claimed upon in the case that a mis-issued certificate is used and causes financial loss.