, 2002-02-13
PKI provides Web users with a false sense of security that undermines the security of their on-line information.
Expand all |
Post comment
PKI - Breaking the Yellow Lock
2002-02-14
Sjonnie (1 replies)
Sjonnie (1 replies)
This is news... how?
2002-02-15
TheReject (2 replies)
TheReject (2 replies)
PKI - Breaking the Yellow Lock
2002-02-17
Exothermic Reaction (2 replies)
Exothermic Reaction (2 replies)

But it can be asserted that even SSL is not highly reliable, since it relies on externally (from the security perspective) managed instrastructure called DNS. A 'bad' or hacked ISP DNS can mislead its users into simple man-in-the-middle attacks.
Coupled with the lack of sound auditing in SSL transferred data, the business risks mount up.
It's time for fundamentally treatment of these mechanisms
[ reply ]
Link to this comment: http://www.securityfocus.com/comments/columns/60/10554#10554