Re: Is SSL/TSL really secure?
- From: Sebastian Gottschalk <seppi@xxxxxxxxx>
- Date: Tue, 28 Mar 2006 15:01:04 +0200
Ludovic Joly wrote:
- people with influence (not to mention governments) might get
beautiful certificates from CAs ("trusted" third parties) and implement
the attack *transparently*, stealing passwords for webmail, etc,
You don't need any influence. Obviously any random telephone caller can
get a Microsoft cert signed by Verisign.
- other security issues regarding certificates are disturbing enough to
consider SSL as insecure for important matters.
What other issues?
.
- Follow-Ups:
- Re: Is SSL/TSL really secure?
- From: Ludovic Joly
- Re: Is SSL/TSL really secure?
- References:
- Is SSL/TSL really secure?
- From: tomodachigai
- Re: Is SSL/TSL really secure?
- From: Volker Birk
- Re: Is SSL/TSL really secure?
- From: Ludovic Joly
- Is SSL/TSL really secure?
- Prev by Date: Re: Question regarding security programming newsgroups
- Next by Date: Re: Is SSL/TSL really secure?
- Previous by thread: Re: Is SSL/TSL really secure?
- Next by thread: Re: Is SSL/TSL really secure?
- Index(es):
Relevant Pages
|