Re: Windows Vista Security Inherently Indeterminate?



In article <4oetg1Fea96iU1@xxxxxxxxxxxxxx>, Sebastian Gottschalk <seppi@xxxxxxxxx> writes:
david20@xxxxxxxxxxxxxxxx wrote:

In article <4oeds5Fe7io6U1@xxxxxxxxxxxxxx>, Sebastian Gottschalk <seppi@xxxxxxxxx> writes:
BC wrote:

I'm sure there will be some clever reverse engineering to get some trusty
utility apps working again, but then clever hackers and virus writers
will probably be able to do likewise.

As I already mentioned, the evil guys can simply aquire a certificate from
VeriSign. Thank you, Microsoft, for choosing the most incompentent CA.

Come on this was over 5 years ago now

http://www.verisign.com/support/advisories/authenticodefraud.html

It was 5 years ago since the still ongoing series of such incidents
started.

Please post details of subsequent incidents where Verisign has signed
certificates for someone falsely claiming to be Microsoft.

I can't say I particularly like any of the CAs and Verisign has abused it's
power in the past - such as with it's wildcarded A records for the .com and
..net top level domains. But still attacking them for this incident with the
"Microsoft certificates" after five years seems excessive.


David Webb
Security team leader
CCSS
Middlesex University
.



Relevant Pages

  • Re: Trying to setup Activesync now cant access /exchange or /remote
    ... Do you want me to send the CEICW log again? ... and then either double-click Certificates or click ... Microsoft CSS Online Newsgroup Support ... This newsgroup only focuses on SBS technical issues. ...
    (microsoft.public.windows.server.sbs)
  • Re: How to fix broken security in Windows 2000?
    ... mvp) post all this stuff? ... >> involved in importing security certificates. ... > and Microsoft code signing are not proof that Microsoft is writing ... > past two days you have said that certs are missing, ...
    (microsoft.public.win2000.windows_update)
  • Re: How to fix broken security in Windows 2000?
    ... mvp) post all this stuff? ... >> involved in importing security certificates. ... > and Microsoft code signing are not proof that Microsoft is writing ... > past two days you have said that certs are missing, ...
    (microsoft.public.security)
  • Re: How to fix broken security in Windows 2000?
    ... mvp) post all this stuff? ... >> involved in importing security certificates. ... > and Microsoft code signing are not proof that Microsoft is writing ... > past two days you have said that certs are missing, ...
    (microsoft.public.win2000.security)
  • RE: GPG and Signing
    ... native S/MIME support into their MUA's, ... I don't believe they own VeriSign. ... Also like other companies, they generally don't support ... for trusted certificates and CA's. ...
    (Debian-User)