Laurie: Improving SSL certificate security
Laurie: Improving SSL certificate security
Posted Apr 3, 2011 16:27 UTC (Sun) by Kit (guest, #55925)In reply to: Laurie: Improving SSL certificate security by geuder
Parent article: Laurie: Improving SSL certificate security
That wouldn't solve the problem of a MITM attack- you're forgetting that the page you're getting is from the _attacker_! If the attacker can get a valid certificate, they can just rewrite the page to make it say that /their/ certificate is valid... after all, the certificate is what is supposed to "prove" the authenticity of the page.
The "social problem" isn't going to be solved by implementing more convoluted systems that the user is simply annoyed/nagged by- any time the user is nagged by security you end up in the ActiveX situation: everyone will just be trained to hit 'yes'/'accept' and totally ignore the text, or the context.
