4 ms·
I think the question you should ask yourself is: how is the NSA involved in the currently established CA system? The answer (to your question) is , the very sam
by leccine 12y ago
I think the question you should ask yourself is: how is the NSA involved in the currently established CA system? The answer (to your question) is , the very same way. Besides, who does think that having an alternative CA provider is going to change anything? The crypto empowering security nowadays is un-trusted, implementations proven containing backdoors, and on the top of that all the implementations are written in languages that can't be formally verified and there are serious security bugs every other week. Back to the topic, what is this new CA group addressing? Which part of this chain that going to be fixed by any mean with this initiative? I guess the answer is none. :)
- codezero 12y agoHow is the NSA involved in the currently established CA system?
- leccine 12y ago2 ways, A, creating rogue cert by md5 collisions (they have the capacity) B, making people believe that a CA guarantees the identity of the issuer, while having their CA in the approved list so they can sign certs (for example like gmail.com) There is good documentation about it: http://files.cloudprivacy.net/ssl-mitm.pdf http://files.cloudprivacy.net/ssl-mitm.pdf
- MichaelGG 12y agoExcept if the NSA did sign Gmail in any non-trivial capacity, it'd certainly be noticed and the offending CA would be removed or put out of business or something like that. Plus it'd draw lots of attention to the NSA directly. If they did want to sign something publicly, they'd just compromise some third-world CA and have them take the blame. There's plenty of them in there. Or they could just sign up as a Comodo reseller.
- leccine 12y agoI think you are missing the point. NSA signs any cert to make it valid for any service. I think you should read that white paper i linked above.
- mreiland 12y agoThe CA's are legally compelled to issue 'global certificates' that always return as valid so they can do MITM attacks at will. It's fairly well documented if you google around. And note, while it may seem like a terrible thing, it really isn't. The issue isn't that they're able to do it, the issue is how rigorous they are with their process of deciding to do it. There is absolutely a valid reason for the government to want to do this.
- perlgeek 12y agoThe NSA almost certainly has a way to sign their own certificates that they use for MITM attacks. But that doesn't mean they gain anything from infiltrating a large number of CAs; after all, those only sign certificates, not create the private keys.
- leccine 12y agoWell, the joke was about how useless is to start a new CA. The first member is going to be the government through a cover agency. Remember, making you believe that SSL makes your service secure is cheaper and better from the NSA point of view than having a huge cluster to crack the encrypted traffic.