Re: [therightkey] DNSNMC deprecates Certificate Authorities and fixes HTTPS security

Leif Johansson <leifj@mnt.se> Mon, 16 December 2013 14:54 UTC

Return-Path: <leifj@mnt.se>
X-Original-To: therightkey@ietfa.amsl.com
Delivered-To: therightkey@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 0694E1AE32E for <therightkey@ietfa.amsl.com>; Mon, 16 Dec 2013 06:54:55 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.599
X-Spam-Level:
X-Spam-Status: No, score=-2.599 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-0.7] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 1yYa9V--ev5V for <therightkey@ietfa.amsl.com>; Mon, 16 Dec 2013 06:54:52 -0800 (PST)
Received: from mail-ee0-f48.google.com (mail-ee0-f48.google.com [74.125.83.48]) by ietfa.amsl.com (Postfix) with ESMTP id C0DDE1AE33D for <therightkey@ietf.org>; Mon, 16 Dec 2013 06:54:51 -0800 (PST)
Received: by mail-ee0-f48.google.com with SMTP id e49so2252064eek.21 for <therightkey@ietf.org>; Mon, 16 Dec 2013 06:54:50 -0800 (PST)
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:message-id:date:from:user-agent:mime-version:to :cc:subject:references:in-reply-to:content-type; bh=QTLhsegX2u1H8P7Yg2FMij2/AHmi8T9dYzcLVuTFDq4=; b=LoXZRVkZxRt/dLVzV69cSpfIuDgx7l2rspIHMc+qzEe3lSL1oqL4SUlowMQsGgcU2M 8WW/fu+zxuFHf2fVXTMJBo4CgVba9gOT6KwQKvM9ZhOtFRi5PbW0WLVTRp845wuVD98p ocKgNHYwniFdxJaXXSfGfUeUDGwHKUS0zv3FDnwzlajsz5m3k6dJGdi2nURKQUwr7T95 256RXbISqZ1Fkn8wiRYiOSpxgdxaW613JXAdLv7XXyVMNu/V4IH61NWaNKcfqWEQByx1 mmNceEGG6oV6dmIKs8q+TgbuIGQo+8r0RxC6XTQ89nCXJ6SXzOSEmEYTD+jswI6aFdGw AETQ==
X-Gm-Message-State: ALoCoQls9fE1RJ9z2aFQFjFvgIVuKW3W3q8qGKusekGVgoDxAAx7onxQc/aQXgEjiOOmdykmToPh
X-Received: by 10.14.113.199 with SMTP id a47mr17416221eeh.41.1387205690625; Mon, 16 Dec 2013 06:54:50 -0800 (PST)
Received: from [193.10.94.23] ([193.10.94.23]) by mx.google.com with ESMTPSA id h3sm43100390eem.15.2013.12.16.06.54.49 for <multiple recipients> (version=TLSv1 cipher=ECDHE-RSA-RC4-SHA bits=128/128); Mon, 16 Dec 2013 06:54:49 -0800 (PST)
Message-ID: <52AF1439.9050800@mnt.se>
Date: Mon, 16 Dec 2013 15:54:49 +0100
From: Leif Johansson <leifj@mnt.se>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:24.0) Gecko/20100101 Thunderbird/24.2.0
MIME-Version: 1.0
To: Phillip Hallam-Baker <hallam@gmail.com>
References: <22429D73-4EFC-4091-8F5B-BAD38968EA54@taoeffect.com> <CAMm+LwiMXdEnHqD0y_S-fP6081Tk=A=7-9LsJQhRuawmmmfdTg@mail.gmail.com> <FEFA307D-97E0-4C58-AB43-5B9AB8E8FC70@taoeffect.com> <CAMm+Lwjwww28tV_qvqQVH3xo1xqvjb6z++258+LOqgxWn-Oh9w@mail.gmail.com> <D0008C27-16EE-41F9-954E-CA51536CD1F0@mnt.se> <CAMm+Lwh-vfvmPaRLQC-9cRyWgUaPmh77KzQU5afBaDc-jCNuEg@mail.gmail.com>
In-Reply-To: <CAMm+Lwh-vfvmPaRLQC-9cRyWgUaPmh77KzQU5afBaDc-jCNuEg@mail.gmail.com>
X-Enigmail-Version: 1.6
Content-Type: multipart/alternative; boundary="------------080104060706060801060907"
Cc: "therightkey@ietf.org" <therightkey@ietf.org>, Tao Effect <contact@taoeffect.com>
Subject: Re: [therightkey] DNSNMC deprecates Certificate Authorities and fixes HTTPS security
X-BeenThere: therightkey@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: <therightkey.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/therightkey>, <mailto:therightkey-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/therightkey/>
List-Post: <mailto:therightkey@ietf.org>
List-Help: <mailto:therightkey-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/therightkey>, <mailto:therightkey-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 16 Dec 2013 14:54:55 -0000

On 2013-12-16 15:31, Phillip Hallam-Baker wrote:
>
>
>
> On Mon, Dec 16, 2013 at 1:32 AM, Leif Johansson <leifj@mnt.se
> <mailto:leifj@mnt.se>> wrote:
>
>
>
>     16 dec 2013 kl. 03:21 skrev Phillip Hallam-Baker <hallam@gmail.com
>     <mailto:hallam@gmail.com>>:
>
>>
>>
>>
>>     On Sun, Dec 15, 2013 at 8:50 PM, Tao Effect
>>     <contact@taoeffect.com <mailto:contact@taoeffect.com>> wrote:
>>
>>>         And for someone who is accusing others of being
>>>         'fraudulent', not a good move to start off repeating figures
>>>         already exposed as bogus like the oft repeated but still
>>>         untrue claim of 600 CAs.
>>
>>         I thought the EFF was a reputable source.
>>
>>         There has been no update or correction to their
>>         post: https://www.eff.org/deeplinks/2011/10/how-secure-https-today
>>
>>
>>     Which kind of calls their credibility into question. HALF the
>>     'CAs' in their graph are from the DFN root. You can check that
>>     out for yourself, it is a German CA that issues certs to higher
>>     education institutions. As has been demonstrated (and agreed by
>>     the EFF people), DFN do not sign certs for key signing keys they
>>     do not hold.
>>
>
>     yep, DFN is a 'private' sub-CA under tight control but it could
>     still be attacked the way diginotar was and though I believe their
>     secuity is a lot better than their less fortunate Dutch cousins, a
>     successful attack would be just as bad.
>
>
>
> That does not excuse 
>
> 1) Failing to examine the issue when the DFN root accounted for half
> of the purported '600 CAs'
>
> 2) Continuing to count the DFN as 300 CAs when they know it is one.
>

agree

>
> Putting out sloppy research and then failing to correct it when a
> mistake is committed is the problem. If someone publishes a flawed
> study I expect them to withdraw it when the errors are pointed out. I
> don't expect them to say that they are going to continue to publish a
> number they know is out by a factor of at least 2 because getting a
> correct number would be too much work.
>
> If people are going to make pointed accusations about the
> trustworthiness of others then they had better not continue to
> knowingly publish false data.
>
>
> As with the 'Al Gore claimed to invent the internet' lie, this has
> become a zombie lie that is repeated to make a political point by
> people who don't really care if what they are saying is true or not.
>
> I think that is a problem. And I am going to continue to point out
> that the EFF is peddling a lie until they withdraw it.
>
> -- 
> Website: http://hallambaker.com/