, 2002-02-13
PKI provides Web users with a false sense of security that undermines the security of their on-line information.
Expand all |
Post comment
PKI - Breaking the Yellow Lock
2002-02-14
Sjonnie (1 replies)
Sjonnie (1 replies)
This is news... how?
2002-02-15
TheReject (2 replies)
TheReject (2 replies)
PKI - Breaking the Yellow Lock
2002-02-17
Exothermic Reaction (2 replies)
Exothermic Reaction (2 replies)

i) The browser will accept a cert, bearing the site name, from any of the CAs the browser recognises (not those the user has chosen to trust)
ii) the domain name and the machine IP address are not securely linked by the cert, but by the independently managed DNS system, which means your local DNS administrator controls where your browser looks for the site.
So, while it's valid to say the CC data is sent securely to a server, the important question is: "Which SSL server?"
And this is exponentially important for high value information, payments and privacy material.
Lyal
[ reply ]
Link to this comment: http://www.securityfocus.com/comments/columns/60/10613#10613