3 ms·
That's the position we start with when we engage with a customer but its dependent on the community in which they are going to communicate with. To be honest in
by rmhrisk 14y ago
That's the position we start with when we engage with a customer but its dependent on the community in which they are going to communicate with. To be honest in most cases today (due to Safari) criticality is not enabled on most deployments.
- tptacek 14y agoArgh.
- lawnchair_larry 14y agoAs far as I'm concerned, that is in fact a MITM cert. Because you can technically MITM. When it comes to crypto and the level of trust that the entire world puts into this, this is the only definition of "MITM cert" that matters.
- tptacek 14y agoYou can only MITM Safari & Opera with that cert, FWIW.
- JoachimSchipper 14y agoThe only browsers you can MITM are Safari and Opera, yes. Stuff like https://crypto.stanford.edu/~dabo/pubs/abstracts/ssl-client-bugs.html https://crypto.stanford.edu/~dabo/pubs/abstracts/ssl-client-... would be worrisome enough without people creating certificates that, according to anyone's best reading of the standards at the time the software was written, should be globally accepted CA's.
- lawnchair_larry 14y agoYou seem to think that SSL is only for browsers.
- tptacek 14y agoI think that to a first approximation CA trust only matters for browsers, because non-browser applications have a whole panoply of other mechanisms that they should already be using to ensure the authenticity of SSL certificates. To put it differently: people running non-browser applications tend to have more control of their destiny. It's interesting that we bring this up, because it makes me now think that maybe the best way to jumpstart TACK is to implement it as a library that IOS programs can use.