Google! DayPop! This is my blogchalk: English, Australia, Sydney, Newtown, Charles, Male, 26-30!

Updated: 4/9/02; 11:13:34 AM

The Desktop Fishbowl
tail -f /dev/mind > blog

Monday, 19 August 2002

I recently wrote this to Bugtraq, about the Recent SSL Vulnerability (It's called an IE vulnerability in the email I was responding to, but since it affected Opera, libssl and Konquerer as well, it's really the "Pretty Much Everything Except Mozilla" vulnerability.)

On Fri, 2002-08-16, robert walker wrote:

A huge amount of infrastructure is managed remotely via SSL and IE these days. It just boggles the mind the extent to which the security integrity of that infrastructure is now under a cloud unknowing

Actually, the SSL vulnerability is a very predictable answer to an old question. For a while now, one of the big “what ifs” of Internet security has been “What if one day, the SSL infrastructure is completely compromised?” The most common hypothetical example of this was the compromise of a Verisign root signing key.

Predictions have ranged from the death of e-commerce, to the end of the world as we know it.

Now, it's not hypothetical any more. Until this is patched and the majority of users upgrade (in other words, give it two years), anyone can forge site certificates that seem valid to 90% of Internet users. The result? The news hasn't reached the “real world” at all. The story has stayed on news-for-nerds websites and in the technical section of mainstream press. E-commerce hasn't skipped a beat.

Certainly none of our1 customers, who were so adamant when we were speccing their web-applications that it must be secured with SSL, have come screaming to us wondering what to do now anyone can man-in-the-middle them.

I'm not sure whether to be saddened or wryly amused. I think I'll go with the latter.

Charles Miller

1 Well, none of mine anyway.

3:54:17 PM    

August 2002
Sun Mon Tue Wed Thu Fri Sat
        1 2 3
4 5 6 7 8 9 10
11 12 13 14 15 16 17
18 19 20 21 22 23 24
25 26 27 28 29 30 31
Jul   Sep

Subscribe to "The Desktop Fishbowl" in Radio UserLand.

Click to see the XML version of this web page.

blogchalk: Charles/Male/26-30. Lives in Australia/Sydney/Newtown and speaks English.

Click here to send an email to the editor of this weblog.

Click here to visit the Radio UserLand website.
theme designed by

Copyright 2002 © Charles Miller