LWN.net Logo

CAs say few people are getting replacements

CAs say few people are getting replacements

Posted Jun 16, 2008 19:34 UTC (Mon) by Los__D (subscriber, #15263)
In reply to: CAs say few people are getting replacements by cortana
Parent article: SSL Certificates Vulnerable to OpenSSL Flaw on Debian (Netcraft)

...and configure their browsers to always do OCSP validation, aborting if there is an error or failure. But that will never happen.
Yeah, a single point of failure is the road to a more flexible and stable Internet *cough*


(Log in to post comments)

CAs say few people are getting replacements

Posted Jun 16, 2008 19:42 UTC (Mon) by cortana (subscriber, #24596) [Link]

It's hardly a single point of failure... it is the CA's job to ensure the high availability of
their responder.

But you highlight the big tradeoff--that between convenience and security. Currently we are
way, way too far into the realm of convenience, and we are paying for it with every data
breach.

CAs say few people are getting replacements

Posted Jun 16, 2008 19:57 UTC (Mon) by Los__D (subscriber, #15263) [Link]

True, but it still limits the points of attack significantly.

To many commercial sites, loss of availability is just as bad (or worse?) than phishers.

You are trading one kind of security for another, not convenience for security.

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds