3 ms·
Someone should probably also point out: most of the CAs are more or less equally 'crappy'. We've been through many CAs now and none of them has a process anywhe
by dgesang 13y ago
Someone should probably also point out: most of the CAs are more or less equally 'crappy'. We've been through many CAs now and none of them has a process anywhere near 'perfect'.
Btw, Comodo customer support is rather nice. We recently bought a code signing certificate from them and they walked us through the whole process via chat, worked quite well and we were done in about 30 min.
- victorf 13y agoDo you not feel that, due to the security failure in 2011, they are one of the worst? I typically disable their certificate on my machines. The CA system is totally flawed anyway, I don't know why I bother.
- overboard 13y agoQuitte the opposite. They themselves came forward about what happened, communicated clearly and took steps to mitigate the problem. From what I saw, they acted responsibly and it has only I erased my trust in them.
- mattlutze 13y agoThat's "increased", yeah?
- majelix 13y ago> The CA system is totally flawed anyway The flaw basically being that people aren't trustworthy, yes? Do you have any alternatives? There's ssh's model, where you just hope it's the right certificate the first time; or maybe mob-source it like WoT?
- pantaril 13y agoThere are flaws with current PKI infrastructure but as you say, it's better than nothing. There are also several initiatives to improve this situation. Google has come with certificate transparency ( http://www.certificate-transparency.org/ http://www.certificate-transparency.org/ ) which essentialy creates public log of all issued certificates so everyone can see and verify that certificates authorities don't issue bogus/fake certificates There is also an idea to use proof of work to estabilish network-wide consensus about valid certificates (like bitcoin or namecoin blockchain). This would be fully decentralised solution.
- victorf 13y agoI like the idea of a blockchain for it, the only downside would be using all that space.
- dgesang 13y agoI didn't know about that incident. Thanks for pointing it out. Here are some references: https://www.schneier.com/blog/archives/2011/03/comodo_group_is.html https://www.schneier.com/blog/archives/2011/03/comodo_group_... https://kb.bluecoat.com/index?page=content&id=SA54&actp=RSS https://kb.bluecoat.com/index?page=content&id=SA54&actp=RSS