4 ms·
2 ways, A, creating rogue cert by md5 collisions (they have the capacity) B, making people believe that a CA guarantees the identity of the issuer, while havin
by leccine 12y ago
2 ways,
A, creating rogue cert by md5 collisions (they have the capacity)
B, making people believe that a CA guarantees the identity of the issuer, while having their CA in the approved list so they can sign certs (for example like gmail.com)
There is good documentation about it:
http://files.cloudprivacy.net/ssl-mitm.pdf http://files.cloudprivacy.net/ssl-mitm.pdf
- MichaelGG 12y agoExcept if the NSA did sign Gmail in any non-trivial capacity, it'd certainly be noticed and the offending CA would be removed or put out of business or something like that. Plus it'd draw lots of attention to the NSA directly. If they did want to sign something publicly, they'd just compromise some third-world CA and have them take the blame. There's plenty of them in there. Or they could just sign up as a Comodo reseller.
- leccine 12y agoI think you are missing the point. NSA signs any cert to make it valid for any service. I think you should read that white paper i linked above.