Is SSL Cert Holder ID Verification A Joke?

InfoSec News <[email protected]> Tue, 24 Jan 2012 03:03:50 -0600 (CST)
Newsgroups gmane.comp.security.attrition.infosec-news
Message-ID <[email protected]>
  This message is in MIME format.  The first part should be readable text,
  while the remaining parts are likely unreadable without MIME-aware tools.

--742952673-885778710-1327395658=:13350
Content-Type: TEXT/PLAIN; FORMAT=flowed; CHARSET=UTF-8
Content-ID: <alpine.DEB.2.02.1201240303392.13497-+lq4ijtN3NWD1tnzEPnUTA@public.gmane.org>
Content-Transfer-Encoding: quoted-printable

http://www.darkreading.com/authentication/167901072/security/news/2325003=
46/is-ssl-cert-holder-id-verification-a-joke.html

By Ericka Chickowski
Contributing Editor
Dark Reading
Jan 24, 2012

With the release of the BEAST exploit and subsequent scrambling by=20
browser vendors to close up vulnerabilities against SSL authentication,=20
many Web authentication discussions have been focused on the SSL/TLS=20
protocol=E2=80=99s weaknesses in recent months. As some IT professionals=20
explain, though, some of the biggest problems with SSL have nothing to=20
do with the technology. Instead, the woes are attributed to poor=20
practices. According to some, one finger should be pointed at=20
certificate authorities, which they say need to do a better job=20
confirming the identity of certificate holders in order to bolster the=20
trust placed in SSL certificates.

=E2=80=9CSSL has been burdened with procedural failures, not technical on=
es. The=20
issue is simple in concept, and complicated in execution: verifying a=20
user's identity can't be done reliably by a machine,=E2=80=9D says Bill H=
orne,=20
who runs William Warren Consulting. =E2=80=9CAt some point, anyone who is=
 trying=20
to convince web users that their PKI certificate is valid must venture=20
into meatspace and show up before a neutral third party to prove that=20
they--or their company--are entitled to use the name that's on their=20
X.509 PKI certificate.=E2=80=9D

Chet Wisniewski, senior security advisor at Sophos, echoes Horne=E2=80=99=
s=20
sentiments, stating that he doesn=E2=80=99t think that the SSL protocol i=
s=20
broken aside from the fact that it relies on the antiquated model of=20
relying on central CAs.

=E2=80=9CThe methods they use to verify your identity are a bit of a joke=
. You=20
can get an SSL certificate for just about anything. For $19, which is=20
what these certs cost, they're domain-validated, which just doesn't mean=20
a lot,=E2=80=9D he says. =E2=80=9CAs far as I'm concerned, having those c=
erts there is=20
better than nothing because it protects you against things like=20
Firesheep. But they should be free and the fact that they say they=20
validate who (the certificate holders) say they are, it=E2=80=99s just ho=
rse=20
manure.=E2=80=9D

[...]


--742952673-885778710-1327395658=:13350
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_____________________________________________________
Did a friend send you this article? Make it your
New Year's Resolution to subscribe to InfoSec News!
http://www.infosecnews.org/mailman/listinfo/isn
--742952673-885778710-1327395658=:13350--