LWN.net Logo

CAs say few people are getting replacements

CAs say few people are getting replacements

Posted Jun 19, 2008 8:38 UTC (Thu) by jschrod (subscriber, #1646)
In reply to: CAs say few people are getting replacements by endecotp
Parent article: SSL Certificates Vulnerable to OpenSSL Flaw on Debian (Netcraft)

OR: https is only used for encryption and server identification doesn't matter.

Even though I updated all problematic SSL certs on all my servers, there were several where it would not have been necessary: There SSL is only used for mailman interfaces of public open mailing lists, and I don't give a damn if that mailman server is impersonated by someone else or not. Risk mitigation is here against transmitting passwords in the clear, not against MiM attacks. (We don't use a publicly well known CA, for starters, but have our own.)

You might have different risk analysis outcome in other situations, but here we chose to decide otherwise and focus on 1st-order risks to confidentiality and cut off at threats on authenticity (and thus downstream 2nd-order confidentiality).


(Log in to post comments)

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds