Updated: 24.11.2002; 12:01:04 Uhr.
disLEXia
lies, laws, legal research, crime and the internet
        

Saturday, March 24, 2001

Re: Bogus Microsoft Corporation digital certificates (Savit, R-21.30)

Microsoft isn't the primary victim, WE ARE!!

The only way to practically resolve this issue is for Verisign to re-issue all certs they ever verified under a new CA signing certificate. THEN, Verisign has to launch a campaign to replace it's CA certs in every online users' web browser!!

Why? Because the general public (us) doesn't have a CRL-checking mechanism when our browsers verify a certificate as valid. Our browsers only look as far as the list of CA certificates that are embedded in our browser at the time we verify a cert.

This isn't a minor PKI flap.

THIS IS HUGE SECURITY DEBACLE FOR VERISIGN, AND A MAJOR NEW VULNERABILITY FOR THE ONLINE PUBLIC AT LARGE!!! [WBH via risks-digest Volume 21, Issue 32]
0:00 # G!


Maximillian Dornseif, 2002.
 
March 2001
Sun Mon Tue Wed Thu Fri Sat
        1 2 3
4 5 6 7 8 9 10
11 12 13 14 15 16 17
18 19 20 21 22 23 24
25 26 27 28 29 30 31
Feb   Apr

Search


Subsections of this WebLog


Subscribe to "disLEXia" in Radio UserLand.

Click to see the XML version of this web page.

Click here to send an email to the editor of this weblog.