4 ms·
Also, ioerror has posted an update in response to Comodo's disclosure: https://blog.torproject.org/blog/detecting-certificate-authority-compromises-and-web-bro
by trotsky 16y ago
Also, ioerror has posted an update in response to Comodo's disclosure:
https://blog.torproject.org/blog/detecting-certificate-authority-compromises-and-web-browser-collusion#Update https://blog.torproject.org/blog/detecting-certificate-autho...
Bottom line is certificate revocation lists and OCSP don't mean anything to an attacker like Iran who is MITM'ing the relevant traffic.
- yuhong 16y agoYea, did the OCSP designers even thinking about the possiblity of MITMing the OCSP itself?
- svlla 16y agoYa, but they didn't figure that implementations would be so brain-dead. From what I can tell, it's not the protocol that's at fault but how browsers handle OCSP failure. It should be a hard error.