4 ms·
> It would be essentially infinitely valuable as a cyberattack target. While I understand what you mean, there are already keys which are "infinitely valuable"
by chacham15 3y ago
> It would be essentially infinitely valuable as a cyberattack target.
While I understand what you mean, there are already keys which are "infinitely valuable": root CA keys. If you have those, you can essentially impersonate anyone. Therefore, we must have ways to protect these sort of keys.
That being said, a root CA key is probably locked up on an air gapped machine vs some machine which actively using the key to scan through traffic.
Mainly pointing out here that the idea of value vs cost has to have some point at which we protect it regardless of the value because thats how the hierarchy of trust works in our CA system.
- andromeduck 3y agobut there are multiple roots
- swexbe 3y agoThere are also multiple countries
- andromeduck 3y agoEscrow compromise as described has a iserial systems failure probability wheres today with root keyts it's parallel. That's weakest link vs isolated/partitioned. CAs have been nuked on occasion without much fanfare to everyday users.
- swexbe 3y agoYou could theoretically set up multiple competing government agencies, each with their own root key. That would deal even with organisational risk.
- lb1lf 3y agoThey've got a ceremony for that! https://www.cloudflare.com/dns/dnssec/root-signing-ceremony/ https://www.cloudflare.com/dns/dnssec/root-signing-ceremony/
- yrro 3y ago> If you have those, you can essentially impersonate anyone. Once. This would be immediately detected through Certificate Transparency and there would be front-page headlines around the world about the chaos that ensued as vendors issued a critical update blocking that CA certificate.