Fraudulent *.google.com certificate issued
Fraudulent *.google.com certificate issued
Posted Aug 30, 2011 19:12 UTC (Tue) by dkg (subscriber, #55359)In reply to: Fraudulent *.google.com certificate issued by butlerm
Parent article: Fraudulent *.google.com certificate issued
intercepting, re-encrypting, and forwarding a large fraction of Google's HTTPS traffic would be a bit of a trick too.
Unless, of course, the adversary is doing a more targeted attack against a specific network they happen to be upstream of.
In that case, they can ignore all the rest of the traffic, and focus their resources on compromising traffic coming out of a network segment they are interested in.
But my larger concern here isn't about Google being compromised. That's bad, but (as the current situation shows) Google actually has the resources and infrastructure to potentially catch when something is going wrong. What about smaller sites? Google vs. a medium-sized government is like King Kong vs. Godzilla. It's not clear who would win. But what if one of these titans turns their focus on small fry? Our current infrastructure suggests a sorry future for the hope of a free and autonomous global network.
Posted Aug 30, 2011 19:38 UTC (Tue)
by raven667 (subscriber, #5198)
[Link] (3 responses)
As long as clients don't accept the upstream keys in the hierarchy changing between requests, to spoof one child domain you have to spoof them all, right?
Posted Aug 30, 2011 22:53 UTC (Tue)
by jebba (guest, #4439)
[Link] (2 responses)
Posted Aug 31, 2011 0:29 UTC (Wed)
by cesarb (subscriber, #6266)
[Link] (1 responses)
(I believe Firefox switched to also caching intermediate certificates because, since Internet Explorer caches intermediate certificates, a lot of people forgot to put the whole chain on their servers, and it "worked" on IE but failed - as it should - on Firefox.)
Posted Aug 31, 2011 1:35 UTC (Wed)
by jebba (guest, #4439)
[Link]
Fraudulent *.google.com certificate issued
Fraudulent *.google.com certificate issued
https://bugzilla.redhat.com/show_bug.cgi?id=732144
Fraudulent *.google.com certificate issued
Fraudulent *.google.com certificate issued