Verisign conflict of interest opposition

digg this!| | Comments (0) | TrackBacks (0)

ICANN Email Archives: [net-rfp-verisign]

See also http://www.financialcryptography.com/mt/archives/000332.html

...Verisign also operates a 'Lawful Intercept' service called
NetDiscovery [2]. This service is provided to "... [assist]
government agencies with lawful interception and subpoena requests
for subscriber records [3]."

We believe that under such a service, VeriSign could be required
to issue false certificates, ones _unauthorised_ by the nominal
owner. Such certificates could be employed in an attack on the
user's traffic via the DNS services now under question. Further,
the design of the SSL browser system includes a 'root list' of
trusted issuers, and a breach of _any_ of these means that the
protection afforded by SSL can now be bypassed.

.....

The cryptographers and security architects who designed the SSL system in 1994 and 1995 envisaged the issuer of certificates to be _trusted by the certificate owner_. This development represents the antithesis of this security requirement.

0 TrackBacks

Listed below are links to blogs that reference this entry: Verisign conflict of interest opposition.

TrackBack URL for this entry: http://juxtaposition.axley.net/blog-bin/mt-tb.cgi/171

Leave a comment

March 2011

Sun Mon Tue Wed Thu Fri Sat
    1 2 3 4 5
6 7 8 9 10 11 12
13 14 15 16 17 18 19
20 21 22 23 24 25 26
27 28 29 30 31    

«« December 2010

Sun Mon Tue Wed Thu Fri Sat
    1 2 3 4 5
6 7 8 9 10 11 12
13 14 15 16 17 18 19
20 21 22 23 24 25 26
27 28 29 30 31    

Archives

Contact: Jason Axley

Search Amazon:

Amazon Logo
Powered by Movable Type 4.1