LWN.net Logo

Multiple authorities

Multiple authorities

Posted Mar 25, 2010 5:20 UTC (Thu) by ncm (subscriber, #165)
Parent article: Blaze: The Spy in the Middle

I might trust a certificate more if it were signed by several independent and mutually hostile authorities. Why can't my browser tell me how many independently-rooted signatures a certificate has? Why shouldn't my bank have its certificate signed by two dozen of them? Shouldn't I be notified if they had two dozen, last time I connected, and now only have two? The more sensitive the service, the more signatures I would like to see. If it takes a full minute at 100% CPU to check them all, fine. I'll put in my password when I'm satisfied, after 15 seconds, or 30, or after it's done.

We should be able to educe some sort of objective, albeit probably noisy, measure of independence, between root authorities by scanning sites.


(Log in to post comments)

Multiple authorities

Posted Mar 25, 2010 20:48 UTC (Thu) by blitzkrieg3 (subscriber, #57873) [Link]

From TFA:
It's worth pointing out that, from the perspective of a law enforcement or intelligence agency, this sort of surveillance is far from ideal. Although current browsers don't ordinarily detect unusual or suspiciously changed certificates, there's no fundamental reason they couldn't (and the Soghoian/Stamm paper proposes a Firefox plugin to do just that).
I would absolutely LOVE to see this. I had no idea that the CA's were willing to sign certs for governmental agencies, but that information is actually not that surprising.

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds