4 ms·
From my understanding of the certificate transparency program does not mitigate the threat of them simply not disclosing a certificate they signed. Ultimately t
by Coxa 7y ago
From my understanding of the certificate transparency program does not mitigate the threat of them simply not disclosing a certificate they signed. Ultimately this still gives them MitM capabilities as long as they control the traffic or am I mistaken?
- DenseComet 7y agoWhen certificates are submitted to CT logs, they are given Signed Certificate Timestamp by the log, which can be attached to the certificate. Chrome and other major browsers require that every certificate has them attached and signed by a trusted log operator, guaranteeing that each certificate is submitted to a CT log. https://github.com/chromium/ct-policy/blob/master/ct_policy.md#qualifying-certificate https://github.com/chromium/ct-policy/blob/master/ct_policy....
- Coxa 7y agoSeems like this is currently disabled in Firefox [1]. Do you have any sources for Safari or MS Edge? [1] https://wiki.mozilla.org/PKI:CT https://wiki.mozilla.org/PKI:CT
- infogulch 7y agoYes, this property (CAs are capable of creating and signing near-arbitrary certs) is inherent in the concept of Certificate Authorities in general, and the log doesn't automatically fix that because nothing can. But auditors regularly check served certificates against these logs and report unlogged certificates automatically. This can be verified in your browser with things like OCSP stapling. You may find this useful: http://www.certificate-transparency.org/how-ct-works http://www.certificate-transparency.org/how-ct-works