Sgt_Kickaxe

msg:4390160 | 7:37 am on Nov 23, 2011 (gmt 0) |
More control for webmasters over their own web properties, I'm all for it. The fewer companies and 3rd party servers required the better. These validated domain-certificate associations are kept on so-called timeline servers and are synchronized with mirrors that are queried by clients. |
| Ah well.
|
tcsoftware

msg:4390203 | 9:59 am on Nov 23, 2011 (gmt 0) |
| In essence, the SK model reduces the number of attack points from hundreds of CAs to 30 or fewer servers where any compromise can be detected automatically. Suspicious entries and other indications of a security breach will cause a compromised server to be immediately ignored by mirrors and clients alike. |
| One good DoS attack and HTTPS breaks for everyone, everywhere!
|
kapow

msg:4390412 | 6:41 pm on Nov 23, 2011 (gmt 0) |
I think the recent Certificate Authority compromises were the tip of a newly emerging iceberg. Funny how the rhetoric goes '...it would take a hacker a zillion years to crack this' Then ...Hacked Do'h!
|
|