Is SSL Cert Holder ID Verification A Joke?
InfoSec News <[email protected]> Tue, 24 Jan 2012 03:03:50 -0600 (CST)
| Newsgroups | gmane.comp.security.attrition.infosec-news |
|---|---|
| Message-ID | <[email protected]> |
This message is in MIME format. The first part should be readable text, while the remaining parts are likely unreadable without MIME-aware tools. --742952673-885778710-1327395658=:13350 Content-Type: TEXT/PLAIN; FORMAT=flowed; CHARSET=UTF-8 Content-ID: <alpine.DEB.2.02.1201240303392.13497-+lq4ijtN3NWD1tnzEPnUTA@public.gmane.org> Content-Transfer-Encoding: quoted-printable http://www.darkreading.com/authentication/167901072/security/news/2325003= 46/is-ssl-cert-holder-id-verification-a-joke.html By Ericka Chickowski Contributing Editor Dark Reading Jan 24, 2012 With the release of the BEAST exploit and subsequent scrambling by=20 browser vendors to close up vulnerabilities against SSL authentication,=20 many Web authentication discussions have been focused on the SSL/TLS=20 protocol=E2=80=99s weaknesses in recent months. As some IT professionals=20 explain, though, some of the biggest problems with SSL have nothing to=20 do with the technology. Instead, the woes are attributed to poor=20 practices. According to some, one finger should be pointed at=20 certificate authorities, which they say need to do a better job=20 confirming the identity of certificate holders in order to bolster the=20 trust placed in SSL certificates. =E2=80=9CSSL has been burdened with procedural failures, not technical on= es. The=20 issue is simple in concept, and complicated in execution: verifying a=20 user's identity can't be done reliably by a machine,=E2=80=9D says Bill H= orne,=20 who runs William Warren Consulting. =E2=80=9CAt some point, anyone who is= trying=20 to convince web users that their PKI certificate is valid must venture=20 into meatspace and show up before a neutral third party to prove that=20 they--or their company--are entitled to use the name that's on their=20 X.509 PKI certificate.=E2=80=9D Chet Wisniewski, senior security advisor at Sophos, echoes Horne=E2=80=99= s=20 sentiments, stating that he doesn=E2=80=99t think that the SSL protocol i= s=20 broken aside from the fact that it relies on the antiquated model of=20 relying on central CAs. =E2=80=9CThe methods they use to verify your identity are a bit of a joke= . You=20 can get an SSL certificate for just about anything. For $19, which is=20 what these certs cost, they're domain-validated, which just doesn't mean=20 a lot,=E2=80=9D he says. =E2=80=9CAs far as I'm concerned, having those c= erts there is=20 better than nothing because it protects you against things like=20 Firesheep. But they should be free and the fact that they say they=20 validate who (the certificate holders) say they are, it=E2=80=99s just ho= rse=20 manure.=E2=80=9D [...] --742952673-885778710-1327395658=:13350 Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _____________________________________________________ Did a friend send you this article? Make it your New Year's Resolution to subscribe to InfoSec News! http://www.infosecnews.org/mailman/listinfo/isn --742952673-885778710-1327395658=:13350--