Re: [therightkey] Barely-capable CAs

Phillip Hallam-Baker <hallam@gmail.com> Thu, 01 November 2012 18:38 UTC

Return-Path: <hallam@gmail.com>
X-Original-To: therightkey@ietfa.amsl.com
Delivered-To: therightkey@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 4781A21F92EE for <therightkey@ietfa.amsl.com>; Thu, 1 Nov 2012 11:38:48 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -3.515
X-Spam-Level:
X-Spam-Status: No, score=-3.515 tagged_above=-999 required=5 tests=[AWL=0.083, BAYES_00=-2.599, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-1]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id IA7Ca3cEVooF for <therightkey@ietfa.amsl.com>; Thu, 1 Nov 2012 11:38:47 -0700 (PDT)
Received: from mail-oa0-f44.google.com (mail-oa0-f44.google.com [209.85.219.44]) by ietfa.amsl.com (Postfix) with ESMTP id 83E8D21F9304 for <therightkey@ietf.org>; Thu, 1 Nov 2012 11:38:47 -0700 (PDT)
Received: by mail-oa0-f44.google.com with SMTP id n5so3111358oag.31 for <therightkey@ietf.org>; Thu, 01 Nov 2012 11:38:47 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=mime-version:in-reply-to:references:date:message-id:subject:from:to :cc:content-type; bh=bM+q2mTdmO1xgLrohDEV5mvhIHjA58AjoRbUsbK9WPk=; b=pKuZmpfCETSGw+a602EMpzPaV1gxBAmlbXGHLvMh0FKydJpmODuMjPJE9jQ8FkMKDN LsPk1u/UchZyH+Lc4I0KjVk9PUvOcmz5e+5ATk8O86VaQng528qgyiskxzF3coK2GEiu q/cOWD+XWEDjyE6EQRYyhL5bJ6QqM9T961rY8I6X963otqmDt6icp5Xpp61yBvAwq8fl ZDiW0ZkIS8PiJoRz5+plMj+AaG2FAEYTFZj1GnL+htVxieKyEdJYej2Yng6VxppjhFHf B1LZNx1jCyCP/qzxCzQ8ae3z+pXd7zDnfNHL8reNyfkhJTsocVOS6TjdazQweOFTCMiq 7DZg==
MIME-Version: 1.0
Received: by 10.60.14.198 with SMTP id r6mr34182349oec.115.1351795127203; Thu, 01 Nov 2012 11:38:47 -0700 (PDT)
Received: by 10.76.27.103 with HTTP; Thu, 1 Nov 2012 11:38:47 -0700 (PDT)
In-Reply-To: <CABrd9SRKuo-VW6AHapz0NogKSGmcXXtRomTh1bvZudaB5q-GTQ@mail.gmail.com>
References: <7500672F-5BDE-4EBE-ABC3-1AFEF2972D95@vpnc.org> <544B0DD62A64C1448B2DA253C0114146069D3FBAE8@TUS1XCHEVSPIN33.SYMC.SYMANTEC.COM> <CAOuvq22PMSq2sAmUBfJcWu6LhEdCA3jKteu38m4UuHbykp7xZw@mail.gmail.com> <544B0DD62A64C1448B2DA253C0114146069D5FC685@TUS1XCHEVSPIN33.SYMC.SYMANTEC.COM> <6DD8CB4F-1233-403D-A27E-F3F80310390F@vpnc.org> <544B0DD62A64C1448B2DA253C0114146069D5FC79B@TUS1XCHEVSPIN33.SYMC.SYMANTEC.COM> <508A48C5.9070005@comodo.com> <544B0DD62A64C1448B2DA253C0114146069D76E5FC@TUS1XCHEVSPIN33.SYMC.SYMANTEC.COM> <CABrd9STHtw__Wm30Z5T27mx8PMb-mScCSa-EZVDdeQvy_Rru1Q@mail.gmail.com> <544B0DD62A64C1448B2DA253C0114146069F66F830@TUS1XCHEVSPIN33.SYMC.SYMANTEC.COM> <CABrd9SSJWm_8BY9uN4D6=LmogwkNeLMZtJaOX2MQU1QuCHJwyg@mail.gmail.com> <80A8F0DC-C894-4299-AEC7-12B84A803E84@vpnc.org> <CAMm+Lwh2Qhv8eHtmy=KisShdJiLYe=ziyfezQELqqfu8y9H5qg@mail.gmail.com> <alpine.BSF.2.00.1211010935330.60568@hiroshima.bogus.com> <CAMm+LwjQiJ3aWpAYdy1hxtf09Sf=4g9AO=r-PihSPVkc8PMLkg@mail.gmail.com> <5092B8C4.3070607@cs.tcd.ie> <CABrd9SRKuo-VW6AHapz0NogKSGmcXXtRomTh1bvZudaB5q-GTQ@mail.gmail.com>
Date: Thu, 01 Nov 2012 14:38:47 -0400
Message-ID: <CAMm+LwhxLYhEJ213AmvTo6cCfPRq_0X1hxJx1vN13nfxkBWLiw@mail.gmail.com>
From: Phillip Hallam-Baker <hallam@gmail.com>
To: Ben Laurie <benl@google.com>
Content-Type: multipart/alternative; boundary="e89a8fb1f72c5db5b304cd735486"
Cc: Lucy Lynch <llynch@civil-tongue.net>, Paul Hoffman <paul.hoffman@vpnc.org>, "therightkey@ietf.org" <therightkey@ietf.org>, Stephen Farrell <stephen.farrell@cs.tcd.ie>
Subject: Re: [therightkey] Barely-capable CAs
X-BeenThere: therightkey@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: <therightkey.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/therightkey>, <mailto:therightkey-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/therightkey>
List-Post: <mailto:therightkey@ietf.org>
List-Help: <mailto:therightkey-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/therightkey>, <mailto:therightkey-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 01 Nov 2012 18:38:48 -0000

Again, does it appear so subtle after it has been discovered?

Would the flaw have been discovered sooner if there was not so much dead
code?


On Thu, Nov 1, 2012 at 2:35 PM, Ben Laurie <benl@google.com> wrote:

> On 1 November 2012 18:00, Stephen Farrell <stephen.farrell@cs.tcd.ie>
> wrote:
> >
> >
> > On 11/01/2012 05:22 PM, Phillip Hallam-Baker wrote:
> >> Having worked in Web security over 20 years now, I have still to see a
> case
> >> where a system was breached because of a really subtle design flaw.
> >
> > Bleichenbacher?
>
> TLS renegotiation?
>
> >
> > S.
> > _______________________________________________
> > therightkey mailing list
> > therightkey@ietf.org
> > https://www.ietf.org/mailman/listinfo/therightkey
>



-- 
Website: http://hallambaker.com/