4 ms·
> Remember: under DNSSEC, Libya would have been BIT.LY's CA. Remember: With or without DNSSEC Libya sets falsified MX records for bit.ly, buys a certificate (w
by soult 15y ago
> Remember: under DNSSEC, Libya would have been BIT.LY's CA.
Remember: With or without DNSSEC Libya sets falsified MX records for bit.ly, buys a certificate (without any hacking), because after all, a valid SSL certificate for domain.example means that someone verified that you indeed receive mail for webmaster@domain.example, and also suddenly has a certificate for Bit.ly. This has been critized by Kaminsky and other researchers for ages now.
I know you love SSL. In fact, I like SSL too. But please stop advertising the CA system along with it, because it is horribly broken.
- tptacek 15y agoYou and I agree about the CA system. SSL admits to things other than the CA system, like notary servers.