4 ms·
it is too hard for me to believe that root ca's have not been compromised when anyone working at these companies could likely easily take it without anyone noti
by asdfasdfasdfa12 10y ago
it is too hard for me to believe that root ca's have not been compromised when anyone working at these companies could likely easily take it without anyone noticing. I do not think transparency has anything at all to do with it.
I think an encryption solutions that cannot be 'broken' for decryption is far more required than one that has the 'good guy' in mind. I do not find it an acceptable solution for critical data.
- satai 10y agoNot any transparency. Certificate transparency. https://en.m.wikipedia.org/wiki/Certificate_Transparency https://en.m.wikipedia.org/wiki/Certificate_Transparency
- asdfasdfasdfa12 10y agoI think we are talking on different lines of thought. I am not concerned with certificate transparency... as the article you point out says it can take a long time [years] before it is found to be compromised. the fact of the matter is, if ssl decryption is possible on the fly, we need a different solution for encryption, this include the use of credit card chip. an encryption scheme cannot be designed to be broken and expect everything to be 'secure' EDIT: I am not being allowed to reply. excuse me, I think you need to read what I wrote more carefully. I do not care about certificate transparency. I must not be communicating clearly I will try again.. I am not referring to the ability to issue a new certificate. I'm talking about the ability to perform SSL decryption without the end user knowing. you do not need to issue a new certificate to do this, you just need the end user to have trusted a new root CA... which brings us to this article where another company is issuing a root CA. do you trust everyone in your 'trusted root ca's on your computer? Here are some ways to untrust certs [0][1]and another conversation on this [2] [0]http://unix.stackexchange.com/questions/285784/untrusting-an-intermediate-ca-in-linux http://unix.stackexchange.com/questions/285784/untrusting-an... [1] https://blog.filippo.io/untrusting-an-intermediate-ca-on-os-x/ https://blog.filippo.io/untrusting-an-intermediate-ca-on-os-... [2] https://news.ycombinator.com/item?id=11781915 https://news.ycombinator.com/item?id=11781915
- satai 10y agoYou can pretty much trust all the root CAs that provide Certificate Transparency. If such a CA went evil such an event would be detected.
- satai 10y agoPlease read it more carefuly: "One of the problems with digital certificate management is that fraudulent certificates take a long time to be spotted, reported and revoked by the browser vendors. Certificate Transparency would help by making it impossible for a certificate to be issued for a domain without the domain owner knowing."