New reflections on Perspectives and notaries ?

Talk about internet security, computer security, personal security, your social security number...
Post Reply
morganism
Senior Member
Posts: 136
Joined: Tue Nov 26, 2013 9:44 pm

New reflections on Perspectives and notaries ?

Post by morganism »

are we going to re-examine the notaries question now that SSL is seriously broken?

http://www.networknotary.org/firefox.html

I can't believe that the open ended string was in TLS !

There is also a 'reverse heartblood"

http://blog.meldium.com/home/2014/4/10/ ... heartbleed

and some history

https://blog.torproject.org/blog/detect ... -collusion
Mozilla/5.0 (Windows NT 6.1; rv:6.0) Gecko/20100101 Firefox/6.0
User avatar
Thrawn
Master Bug Buster
Posts: 3106
Joined: Mon Jan 16, 2012 3:46 am
Location: Australia
Contact:

Re: New reflections on Perspectives and notaries ?

Post by Thrawn »

Actually TLS is in the process of being fixed.

And Perspectives wouldn't help very much against this, because even if you're using the correct certificate, someone who has stolen the private key can read your traffic on the wire, just like the true server can.
======
Thrawn
------------
Religion is not the opium of the masses. Daily life is the opium of the masses.

True religion, which dares to acknowledge death and challenge the way we live, is an attempt to wake up.
Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:28.0) Gecko/20100101 Firefox/28.0
dhouwn
Bug Buster
Posts: 968
Joined: Thu Mar 19, 2009 12:51 pm

Re: New reflections on Perspectives and notaries ?

Post by dhouwn »

An issue is that certificates can't be reliably revoked. Perspectives might help with that a bit?
Mozilla/5.0 (Windows NT 6.3; WOW64; rv:28.0) Gecko/20100101 Firefox/28.0
Post Reply