Rabu, 23 Maret 2011

Detecting Certificate Authority compromises and web browser collusion

The Tor Project has long understood that the certification authority (CA) model of trust on the internet is susceptible to various methods of compromise. Without strong anonymity, the ability to perform targeted attacks with the blessing of a CA key is serious. In the past, I’ve worked on attacks relating to SSL/TLS trust models and for quite some time, I’ve hunted for evidence of non-academic CA

Tidak ada komentar:

Posting Komentar