BugTraq
International Domain Name [IDN] support in modern browsers allows attackers to spoof domain name URLs + SSL certs. Feb 08 2005 04:39AM
Brandon Kovacs (liljoker771 gmail com) (2 replies)
Re: International Domain Name [IDN] support in modern browsers allows attackers to spoof domain name URLs + SSL certs. Feb 09 2005 03:31PM
Will Kamishlian (will will-k com) (1 replies)
Re: International Domain Name [IDN] support in modern browsers allows attackers to spoof domain name URLs + SSL certs. Feb 10 2005 11:24AM
Peter J. Holzer (hjp wsr ac at) (1 replies)
Re: International Domain Name [IDN] support in modern browsers allows attackers to spoof domain name URLs + SSL certs. Feb 11 2005 07:07PM
Scott Gifford (sgifford suspectclass com) (2 replies)
Re: International Domain Name [IDN] support in modern browsers allows attackers to spoof domain name URLs + SSL certs. Feb 11 2005 10:44PM
Neil W Rickert rickert+bt (at) cs.niu (dot) edu [email concealed] (rickert+bt cs niu edu) (2 replies)
RE: International Domain Name [IDN] support in modern browsers allows attackers to spoof domain name URLs + SSL certs. Feb 13 2005 12:32AM
David Schwartz (davids webmaster com) (1 replies)
Re: International Domain Name [IDN] support in modern browsers allows attackers to spoof domain name URLs + SSL certs. Feb 15 2005 08:12AM
Vincent Archer (var deny-all com) (2 replies)
Re: International Domain Name [IDN] support in modern browsers allows attackers to spoof domain name URLs + SSL certs. Feb 12 2005 04:03AM
Scott Gifford (sgifford suspectclass com) (1 replies)
Re: International Domain Name [IDN] support in modern browsers allows attackers to spoof domain name URLs + SSL certs. Feb 15 2005 07:00PM
bkfsec (bkfsec sdf lonestar org) (2 replies)
Re: International Domain Name [IDN] support in modern browsers allows attackers to spoof domain name URLs + SSL certs. Feb 15 2005 08:44PM
Gwendolynn ferch Elydyr (gwen reptiles org) (1 replies)
Re: International Domain Name [IDN] support in modern browsers allows attackers to spoof domain name URLs + SSL certs. Feb 15 2005 08:49PM
bkfsec (bkfsec sdf lonestar org) (1 replies)
Re: International Domain Name [IDN] support in modern browsers allows attackers to spoof domain name URLs + SSL certs. Feb 16 2005 03:28PM
Gwendolynn ferch Elydyr (gwen reptiles org) (2 replies)
Re: International Domain Name [IDN] support in modern browsers allows attackers to spoof domain name URLs + SSL certs. Feb 16 2005 03:48PM
bkfsec (bkfsec sdf lonestar org) (1 replies)
Re: International Domain Name [IDN] support in modern browsers allows attackers to spoof domain name URLs + SSL certs. Feb 16 2005 06:49PM
Gwendolynn ferch Elydyr (gwen reptiles org) (1 replies)
On Wed, 16 Feb 2005, bkfsec wrote:
> The local BBB is accountable to local laws. CAs are spread throughout the
> world and are global in nature. As a member of a local community, I can
> choose to familiarize myself with those regulations, understand them, and use
> them against the BBB if they violate their trust. I can also choose to go on
> a crusade against the local BBB.
>
> I think that deep down we're agreeing on the point that they're inherently
> untrustworthy. My point in saying "if you take my meaning" was to hi-light
> that rather than focus on this relatively minor nitpicking of point. I'm not
> the first one in this thread to bring up the BBB. So take your point up with
> the person who did bring it up, please.

Actually I'm just trying to be explicitly clear about the path that
you're using for trust. The BBB just happens to be the example that
you'd used as an organization that you'd trust more than your average CA.

As I'm reading you, you're saying that you:

(1) trust establishments that you can see and touch more
than you trust establishments that you can't see or touch.

(2) trust establishments that are bound by a legal system that
you're familiar with more than establishments that are bound
by a legal system that you aren't familiar with.

IMHO the question is more about what your particular grounds for trust
happen to be than whether CAs are all/partially/not trustworthy - or
if the BBB in your area happens to be trustworthy.

Personally I'd really debate the concept that physical proximity is
in any respect grounds for trust - and that familiarity implies the same.

I'd be far more inclined to suggest using consistent long term behaviour
as a predictor - and implementing a system where significant incentives
towards desired behaviour exist.

cheers!
========================================================================
==
"A cat spends her life conflicted between a deep, passionate and profound
desire for fish and an equally deep, passionate and profound desire to
avoid getting wet. This is the defining metaphor of my life right now."

[ reply ]


 

Privacy Statement
Copyright 2010, SecurityFocus