BugTraq
International Domain Name [IDN] support in modern browsers allows attackers to spoof domain name URLs + SSL certs. Feb 08 2005 04:39AM
Brandon Kovacs (liljoker771 gmail com) (2 replies)
Re: International Domain Name [IDN] support in modern browsers allows attackers to spoof domain name URLs + SSL certs. Feb 09 2005 03:31PM
Will Kamishlian (will will-k com) (1 replies)
Re: International Domain Name [IDN] support in modern browsers allows attackers to spoof domain name URLs + SSL certs. Feb 10 2005 11:24AM
Peter J. Holzer (hjp wsr ac at) (1 replies)
Re: International Domain Name [IDN] support in modern browsers allows attackers to spoof domain name URLs + SSL certs. Feb 11 2005 07:07PM
Scott Gifford (sgifford suspectclass com) (2 replies)
Re: International Domain Name [IDN] support in modern browsers allows attackers to spoof domain name URLs + SSL certs. Feb 11 2005 10:44PM
Neil W Rickert rickert+bt (at) cs.niu (dot) edu [email concealed] (rickert+bt cs niu edu) (2 replies)
RE: International Domain Name [IDN] support in modern browsers allows attackers to spoof domain name URLs + SSL certs. Feb 13 2005 12:32AM
David Schwartz (davids webmaster com) (1 replies)
Re: International Domain Name [IDN] support in modern browsers allows attackers to spoof domain name URLs + SSL certs. Feb 15 2005 08:12AM
Vincent Archer (var deny-all com) (2 replies)
Re: International Domain Name [IDN] support in modern browsers allows attackers to spoof domain name URLs + SSL certs. Feb 12 2005 04:03AM
Scott Gifford (sgifford suspectclass com) (1 replies)
Re: International Domain Name [IDN] support in modern browsers allows attackers to spoof domain name URLs + SSL certs. Feb 15 2005 07:00PM
bkfsec (bkfsec sdf lonestar org) (2 replies)
Re: International Domain Name [IDN] support in modern browsers allows attackers to spoof domain name URLs + SSL certs. Feb 15 2005 08:44PM
Gwendolynn ferch Elydyr (gwen reptiles org) (1 replies)
Re: International Domain Name [IDN] support in modern browsers allows attackers to spoof domain name URLs + SSL certs. Feb 15 2005 08:49PM
bkfsec (bkfsec sdf lonestar org) (1 replies)
Re: International Domain Name [IDN] support in modern browsers allows attackers to spoof domain name URLs + SSL certs. Feb 16 2005 03:28PM
Gwendolynn ferch Elydyr (gwen reptiles org) (2 replies)
Re: International Domain Name [IDN] support in modern browsers allows attackers to spoof domain name URLs + SSL certs. Feb 16 2005 03:48PM
bkfsec (bkfsec sdf lonestar org) (1 replies)
Gwendolynn ferch Elydyr wrote:

>> Well, I meant more accountable than CAs are. I still think that that
>> statement is accurate if you take my meaning.
>
>
> Actually I don't take your meaning. I'd appreciate it if you could
> spell out why you think that one organization paid to provide trust is
> different from another organization paid to provide trust.
>

Simple: relative physical location.

The local BBB is accountable to local laws. CAs are spread throughout
the world and are global in nature. As a member of a local community, I
can choose to familiarize myself with those regulations, understand
them, and use them against the BBB if they violate their trust. I can
also choose to go on a crusade against the local BBB.

Listen, I'm sure that you have a bone to pick with the BBB and I have no
quarrel with that. My point isn't that the BBB is a reputable, great
organization (I don't really believe that it is). My point is that the
CAs aren't trustworthy in that way and are even less trustworthy in my
view than the BBB.

I think that deep down we're agreeing on the point that they're
inherently untrustworthy. My point in saying "if you take my meaning"
was to hi-light that rather than focus on this relatively minor
nitpicking of point. I'm not the first one in this thread to bring up
the BBB. So take your point up with the person who did bring it up, please.

-Barry

[ reply ]


 

Privacy Statement
Copyright 2010, SecurityFocus