3 ms·
Didn't the slides show that it was the Diginotar compromise? > We cannot have untrustworthy CAs in a system based on trust. That's simply not an option. The e
by lambda 13y ago
Didn't the slides show that it was the Diginotar compromise?
> We cannot have untrustworthy CAs in a system based on trust. That's simply not an option.
The entire CA trust model is broken. In the trust model, any CA can issue certs for any domain; so a Chinese CA could issue Google certs, or a US CA could issue certs for the Dutch government.
Self-signed certs with certificate pinning are indeed more likely to be secure than CA certs. Of course, you can do both; CA signed certs (which does add a small amount of trustworthiness, as the CA is at least supposed to do a little work to verify a real-world identity), and use certificate pinning to avoid this kind of attack.
- jlgaddis 13y agoDANE[0] (in combination w/ DNSSEC[1]) is starting to sound really good right about now... except that, you know, the U.S. also runs several root nameservers. [0]: https://tools.ietf.org/html/rfc6698 https://tools.ietf.org/html/rfc6698 [1]: https://en.wikipedia.org/wiki/Domain_Name_System_Security_Extensions https://en.wikipedia.org/wiki/Domain_Name_System_Security_Ex...
- dsl 13y agoRoot servers simply serve the content for the root zone, ICANN generates the contents of the root zone and signs it using an elaborate system of trust: http://dns.icann.org/ksk/ http://dns.icann.org/ksk/