Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The DigiNotar case was an anomaly where the certificate provider was compromised. This is a rare case.


It's nowhere near as rare as you think. There are sub-CA certs issued to private companies all the time, allowing them to MITM any default browser config.

The PKI is now totally broken.


http://www.infoworld.com/t/authentication/weaknesses-in-ssl-...

Seems to happen often enough.

(Then again, 2011 seems to have been something of an unlucky year for security professionals. Just ask RSA.)


Well you got to trust someone... else you should just unplug your computer from the internet :)




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: