BugTraq
International Domain Name [IDN] support in modern browsers allows attackers to spoof domain name URLs + SSL certs. Feb 08 2005 04:39AM
Brandon Kovacs (liljoker771 gmail com) (2 replies)
Re: International Domain Name [IDN] support in modern browsers allows attackers to spoof domain name URLs + SSL certs. Feb 09 2005 03:31PM
Will Kamishlian (will will-k com) (1 replies)
Re: International Domain Name [IDN] support in modern browsers allows attackers to spoof domain name URLs + SSL certs. Feb 10 2005 11:24AM
Peter J. Holzer (hjp wsr ac at) (1 replies)
Re: International Domain Name [IDN] support in modern browsers allows attackers to spoof domain name URLs + SSL certs. Feb 11 2005 07:07PM
Scott Gifford (sgifford suspectclass com) (2 replies)
Re: International Domain Name [IDN] support in modern browsers allows attackers to spoof domain name URLs + SSL certs. Feb 11 2005 10:44PM
Neil W Rickert rickert+bt (at) cs.niu (dot) edu [email concealed] (rickert+bt cs niu edu) (2 replies)
RE: International Domain Name [IDN] support in modern browsers allows attackers to spoof domain name URLs + SSL certs. Feb 13 2005 12:32AM
David Schwartz (davids webmaster com) (1 replies)
Re: International Domain Name [IDN] support in modern browsers allows attackers to spoof domain name URLs + SSL certs. Feb 15 2005 08:12AM
Vincent Archer (var deny-all com) (2 replies)
Re: International Domain Name [IDN] support in modern browsers allows attackers to spoof domain name URLs + SSL certs. Feb 12 2005 04:03AM
Scott Gifford (sgifford suspectclass com) (1 replies)
Re: International Domain Name [IDN] support in modern browsers allows attackers to spoof domain name URLs + SSL certs. Feb 15 2005 07:00PM
bkfsec (bkfsec sdf lonestar org) (2 replies)
Re: International Domain Name [IDN] support in modern browsers allows attackers to spoof domain name URLs + SSL certs. Feb 15 2005 08:44PM
Gwendolynn ferch Elydyr (gwen reptiles org) (1 replies)
Re: International Domain Name [IDN] support in modern browsers allows attackers to spoof domain name URLs + SSL certs. Feb 15 2005 08:49PM
bkfsec (bkfsec sdf lonestar org) (1 replies)
Gwendolynn ferch Elydyr wrote:

> On Tue, 15 Feb 2005, bkfsec wrote:
>
>> The difference between CAs and the BBB is that the BBB is well known
>> and highly accountable. CAs are not necessarily. There is no widely
>> screened public discussion or understanding of the function of CAs.
>> The accepted root CAs do their jobs on the browser entirely in the
>> background. Their "seal of approval" is considered implicit by the
>> lack of a message at all.
>
>
> The BBB is certainly well known, but describing it as highly accountable
> is certainly inaccurate. A quick web search will inform you that the
> BBB has local 'affiliates', and that the quality of these 'affiliates'
> can vary dramatically from location to location.
>
> There's no widely screened public discussion or understanding of the
> function of the BBB - and their seal of approval certainly appears on
> sites and businesses they've never heard of.
>
>
Well, I meant more accountable than CAs are. I still think that that
statement is accurate if you take my meaning.

-Barry

[ reply ]


 

Privacy Statement
Copyright 2010, SecurityFocus