Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
PKI - Breaking the Yellow Lock
Richard Forno, 2002-02-13

PKI provides Web users with a false sense of security that undermines the security of their on-line information.

Submit Comment Mode:
Name:
Subject:
Message:
 
  Enter the characters that appear above
 
PKI - Breaking the Yellow Lock 2002-02-23
Anonymous
2 issues I see:
i) The browser will accept a cert, bearing the site name, from any of the CAs the browser recognises (not those the user has chosen to trust)
ii) the domain name and the machine IP address are not securely linked by the cert, but by the independently managed DNS system, which means...

[ more ]  





 

Privacy Statement
Copyright 2009, SecurityFocus