LWN.net Logo

Certificates and "authorities"

Certificates and "authorities"

Posted Sep 9, 2011 0:22 UTC (Fri) by gerv (subscriber, #3376)
In reply to: Certificates and "authorities" by rgmoore
Parent article: Certificates and "authorities"

"Do you really think the official Dutch CA is going to turn down a government request for a false Cert, especially if it's presented as being for some important and legitimate government purpose like tracking thieves or terrorists?"

Perhaps not, but everyone who gets MITMed by it gets sent a copy of the certificate, which is non-repudiable evidence about what the CA did. Publish the cert, and the CA's untrustworthiness is exposed for all to see. A few tools so that some people are more likely to notice this, and suddenly it becomes a very business-risky thing for a CA to consent to do.

And if a government blows up all the CAs in its jurisdiction like this (and believe me, CAs 2-N will flee when they see what happened to CA 1) then the attack no longer works for them.


(Log in to post comments)

Certificates and "authorities"

Posted Sep 9, 2011 1:12 UTC (Fri) by Nelson (subscriber, #21712) [Link]

Unless the government request is accompanied by piles of cash, in which case other CAs might want in on the action.

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds