MESSAGE
DATE | 2002-01-26 |
FROM | Ruben Safir
|
SUBJECT | Subject: [hangout] Fwd: Re: [wwwac] Suggestions for SSL Certificate Authorities [wwwac@underwood.electricmindcontrol.net]
|
Can someone help this poor lost soul....
He's very confused about certificates for the web and asymetric encryption
On 2002.01.26 21:17:56 -0500 Tim wrote: No, it doesn't.
It works like this:
* I roll my own certificate.
* Jon Q. Hacker decides to impersonate me.
* Jon Q. Hacker redirects some DNS to a clone of my site. (details of this left as an exercise- maybe he just registers a type-URL, whatever.)
* Jon Q. Hacker rolls his own certificate with my name on it
* Ruben types my URL, but the compromised DNS points to JQH's box. Certificate says "Tim". Ruben tells JQH confidential stuff meant only for me (Tim).
With a third party such as verisign, you have verisign's signature on the particular certificate I send. JQH can still send you a certificate, but it won't be signed. The signature of the trusted third party tells the user that the key they're receiving to communicate with me as actually MINE, not just one with my name on it.
Anyhow, I'm not interested in rolling my own. The question still remains:
Any suggestions on a good CA to use?
-TIm
At 08:57 PM 1/26/2002 -0500, Ruben Safir wrote:
>On 2002.01.26 20:56:59 -0500 Tim wrote: > >>Kinda defeats the purpose of have a cert, doesn't it? > >Not at all. > >Public key assymetric cryptografy solves the problem >totally without the need for a third party involved. > >Of couse, if you trust verisign, you should know they have >given away Microsoft certificates to anyone who knocks on >their door and asks. > >:) > > >No THAT defeats the purpose of the certificate. > >-- >__________________________ > >Brooklyn Linux Solutions >__________________________ >http://www.mrbrklyn.com - Consulting >http://www.brooklynonline.com - For the love of Brooklyn >http://www.nylxs.com - Leadership Development in Free Software >http://www.nyfairuse.org - The foundation of Democracy >http://www2.mrbrklyn.com/resources - Unpublished Archive or stories and >articles from around the net >http://www2.mrbrklyn.com/mp3/hooked.mp3 - Spring is coming.... >http://www2.mrbrklyn.com/downtown.html - See the New Downtown Brooklyn.... > >1-718-382-5752 > > > > > >## The World Wide Web Artists' Consortium --- http://www.wwwac.org/ ## >## To Unsubscribe, send an e-mail to: wwwac-unsubscribe-at-lists.wwwac.org ## -- __________________________
Brooklyn Linux Solutions __________________________ http://www.mrbrklyn.com - Consulting http://www.brooklynonline.com - For the love of Brooklyn http://www.nylxs.com - Leadership Development in Free Software http://www.nyfairuse.org - The foundation of Democracy http://www2.mrbrklyn.com/resources - Unpublished Archive or stories and articles from around the net http://www2.mrbrklyn.com/mp3/hooked.mp3 - Spring is coming.... http://www2.mrbrklyn.com/downtown.html - See the New Downtown Brooklyn....
1-718-382-5752
____________________________ New Yorker Linux Users Scene Fair Use - because it's either fair use or useless....
|
|