4 ms·
It is. There will also be a high incentive for hackers to attack at take control of some certificate autorities. And it will be worse than accepting self signed
by zer0gravity 10y ago
It is. There will also be a high incentive for hackers to attack at take control of some certificate autorities. And it will be worse than accepting self signed certificates as trusted solutions...
- nathanaldensr 10y agoWouldn't hackers already have that incentive? It seems like virtually all sites worth targeting would already be secured by TLS certificates, so the remaining sites wouldn't provide much value to hackers.
- zer0gravity 10y agoThey would. And apparently they're doing it with some success, judging by all the passwords leaked lately. We can assume there were other "successes" that were not made public yet.. So yeah.. enforcing https may be the same as trying to patch a hole when the bag is wide open.. It will simply become even less feasible for sombody to host a site without the blessing of the big cert guys... Federalization of the internet is where we are going, but I susppose that's just the faith of all media channels..
- dylanfw 10y agoIn what way are you connecting recent password dumps to hackers attacking Certificate Authorities? If someone controlled the CA, they would also need to control the target website and/or the victim's home network in order to MITM the connection and snag the credentials. Also, this would allow them to capture plaintext passwords and as far as I know all of the major password dumps recently have been hashed passwords indicating that the database was breached, not that a CA was compromised and thousands of users were MITMed.