Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Or, what if the user's browser requested a site's public key on its first visit, but required it to be signed with a trusted CA? So to perform a MITM on an SSL connection, Mallory would have to both infiltrate a CA and MITM the user's connection on their first visit to a site.


You can have this today by running Firefox with the Certificate Patrol plugin.


Though the system I suggested lets a site change CA.


When a site's certificate changes, Certificate Patrol shows you what has changed, including the public key fingerprint. So you easily detect the case when the site changes CA without changing their public key.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: