RE: WAS: Bittorrent - utorrent NOW: Certificate Talk



Another point is the big guys provide insurance. If your encryption is
cracked they cover damages up to whatever amount. That's the only plus
(I see) to using one of the larger certificate companies.



-----Original Message-----
From: listbounce@xxxxxxxxxxxxxxxxx [mailto:listbounce@xxxxxxxxxxxxxxxxx]
On Behalf Of Tremaine Lea
Sent: Sunday, March 18, 2007 6:41 PM
To: Randal T.Rioux
Cc: focus-ids@xxxxxxxxxxxxxxxxx
Subject: Re: WAS: Bittorrent - utorrent NOW: Certificate Talk


On 18-Mar-07, at 12:45 AM, Randal T. Rioux wrote:

Tremaine Lea wrote:
Having said that, the BCSG *will* refuse self-signed certs and
expired
certs etc.


That is the stupidest thing I've ever heard. Honestly, a paid-for cert
is barely more trustworthy than a self-signed cert. The entire cert
system is broken by design, and benefits nobody but the money
collectors
at the major companies (VeriSign, Entrust, etc).

Can somebody convince me that my understanding is mistaken?

Thanks,
Randy





It's as stupid as IE7's handling of it really. Without a better
understanding of the certification process by the end user, the
benefits are certainly not as clear. Certainly it prevents MITM
issues during the https transaction, but that may be about it with
some exceptions. With IE7 it can certainly produce problems on an
internal network, at least initially. IE7 will actually refuse to
connect you with the site. Bluecoat at least provides you with the
opportunity to exclude a network from checks, like your own.


On the pros side of the fence, with a paid certificate such as those
through Verisign, the benefit over a self signed cert is a lot
clearer. Unfortunately there are companies that will hand you a cert
with very little in the way of verification which destroys the
usefulness of it. Self signed certs are useful in instances where
you trust the issuer to begin with, or in corporate networks. For a
small company trying to establish an ecommerce presence however, they
have not yet earned the trust or established themselves to the point
where jane and joe intertubes can (or should?) trust them.

Tremaine

------------------------------------------------------------------------
Test Your IDS

Is your IDS deployed correctly?
Find out quickly and easily by testing it
with real-world attacks from CORE IMPACT.
Go to
http://www.coresecurity.com/index.php5?module=Form&action=impact&campaig
n=intro_sfw
to learn more.
------------------------------------------------------------------------


------------------------------------------------------------------------
Test Your IDS

Is your IDS deployed correctly?
Find out quickly and easily by testing it
with real-world attacks from CORE IMPACT.
Go to http://www.coresecurity.com/index.php5?module=Form&action=impact&campaign=intro_sfw
to learn more.
------------------------------------------------------------------------



Relevant Pages

  • Re: SSL Certificate not trusted by Windows Mobile 6
    ... pretty tired of some devices not trusting CA A, ... if you go directly to the cert file. ... free certificate that comes with SBS! ... I have an equifax secure CA on my windows mobile. ...
    (microsoft.public.windows.server.sbs)
  • Re: Digital verification of authentic documents ?
    ... >> sure the cert is from a trusted source. ... Depends on certificate issuer, if it's ... trust MS, and 2 you don't trust verisign. ... Hence why you where called a troll. ...
    (comp.security.misc)
  • Re: iPaq 5555 WPA Authentication
    ... Auto-enrollement would leave the certs on the machine. ... auto-enrollment is used to give the network admin some slck when it comes to ... After that the cert should always be ... >> It sounds like you need to add a user certificate to access the ap, ...
    (microsoft.public.pocketpc.wireless)
  • Re: ADFS Token-signing Certs Not in Trusted Root Store
    ... This is good info, Joe. ... So now I know that the token-signing certificate is ... Get a signing cert from a CA ... case, you never have to worry about expiration or CRL checking, as your cert ...
    (microsoft.public.windows.server.active_directory)
  • Re: Issues with SSL on Win CE 5.0
    ... the HKCU certificate store. ... and tell the web server to use it. ... The old cert was in. ...
    (microsoft.public.windowsce.embedded)