Laurie: Improving SSL certificate security
Laurie: Improving SSL certificate security
Posted Apr 6, 2011 9:26 UTC (Wed) by jamesh (guest, #1159)In reply to: Laurie: Improving SSL certificate security by geuder
Parent article: Laurie: Improving SSL certificate security
It shouldn't have been possible to for the attacker to create Domain Validated certificates, but they managed to due to policy problems (possibly due to them outsourcing the validation to a reseller?).
For EV certificates, we're being told that they are more secure because the CAs would never take similar shortcuts when validating these new certificates.
The existing track record of CAs doesn't inspire confidence that we'll never see a bogus EV certificate.
