4 ms·
This article is a bit late. Anyone who has been keeping up with the Diginotar etc stuff knows that: 1, Diginotar is dead in the water now (they've been effecti
by Woost 15y ago
This article is a bit late. Anyone who has been keeping up with the Diginotar etc stuff knows that:
1, Diginotar is dead in the water now (they've been effectively killed off by browser vendors)
2. The exact problem here is very well known. That is, the problems with the SSL system having trusted authorities, and the number of companies trusted to issue certificates. (any trusted company can issue a cert for any domain it chooses)
3. This problem has already happened before with other certificate vendors, the only difference here is that Diginotar is a small enough fish that browser vendors are reacting (see, for example: http://www.theregister.co.uk/2008/12/29/ca_mozzilla_cert_snaf/ http://www.theregister.co.uk/2008/12/29/ca_mozzilla_cert_sna... in 2008) Oh, and that Diginotar was silent on the breach.
And I like his boasting...sounds to me like a misquote or a script kiddie.