3 ms·
Are any of the other providers this big? 10% of all websites and growing. If the NSA get hold of the keys then it's just like the old days, or am I missing some
by niks1101 7y ago
Are any of the other providers this big? 10% of all websites and growing. If the NSA get hold of the keys then it's just like the old days, or am I missing something?
- deleted 7y ago[deleted]
- derefr 7y ago> If the NSA get hold of the keys In X.509, the CA never sees the private key associated with a certificate. So while a state actor could always manufacture a “legitimate CA-signed” replacement cert and MITM you with it, they can’t do anything about modern defense-in-depth security approaches like certificate pinning, since it’s the particular public key of the original cert being pinned, not the CA’s authority + CN.
- tialaramex 7y agoPinning can be used with anything in the chain not just your leaf. Some pinning strategies assume a particular CA is trustworthy and pin the public key for that CA, so that they don't need to update with new pins just because they got a new certificate. Obviously you do need to stay on your toes (if you pinned Symantec and then it got distrusted... need to get new pins pronto) but that's true for any pinning strategy. Laziness plus pinning is a bad combination. Like er... keeping tigers as pets and having a toddler maybe?
- bluesign 7y agoIt would not work for mass data collection, maybe only on targeted attacks.
- JMTQp8lwXL 7y agoConsidering 90% of websites aren't served by LE certificates, I wouldn't be surprised to hear if one of the legacy issuers had a larger market share.
- blattimwind 7y ago> https://www.netcraft.com/images/2015/11/certauth_all.png https://www.netcraft.com/images/2015/11/certauth_all.png (January 2015)