3 ms·
> “[W]e’re compelled by industry policies to revoke certs when we become aware that the private key has been communicated to a 3rd-party and thus could be used
by venus 13y ago
> “[W]e’re compelled by industry policies to revoke certs when we become aware that the private key has been communicated to a 3rd-party and thus could be used by that party to intercept and decrypt communications”
This raises an interesting possibility of civil disobedience. Imagine if there was a site hosted in, say, russia, which received tip-offs from NSL recipients about these SSL seizures. And imagine they then informed the SSL issuers, who would revoke the certs, rendering the old ones useless and forcing the FBI back into court, with no-one to point a finger at.
I suppose the FBI would just request an order for all future certs as well.
- shubb 13y agoWell, the finger is pointing at the NSL recipients. They are supposed to be the only people that know about the order, so they carry the can if it gets leaked.
- venus 13y agoThere'd be a lot of people inside the FBI with knowledge. Proving it was an NSL recipient, let alone nailing down which one, would be difficult if not impossible in court. Snowden's leaked a whole lot more than any NSL recipient ever did...
- tankenmate 13y agoIn that case you could use flapping certificates as a dead man's switch.
- malandrew 13y agoflapping certificates?
- tankenmate 13y agoIf the certificate keeps changing, regardless of whether it is valid and/or expired, then it is an indicator that not all is well.