{"id":830,"date":"2011-08-30T22:16:55","date_gmt":"2011-08-31T05:16:55","guid":{"rendered":"http:\/\/upon2020.com\/?p=830"},"modified":"2011-08-30T22:16:55","modified_gmt":"2011-08-31T05:16:55","slug":"its-time-to-abolish-ssl-certificate-authorities","status":"publish","type":"post","link":"https:\/\/upon2020.com\/blog\/2011\/08\/its-time-to-abolish-ssl-certificate-authorities\/","title":{"rendered":"It&#8217;s Time To Abolish SSL Certificate Authorities"},"content":{"rendered":"<p>Yet another <a href=\"http:\/\/blog.mozilla.com\/security\/2011\/08\/29\/fraudulent-google-com-certificate\/\">case<\/a> this week where unsuspecting users were compromised because a certificate authority that they had never heard of screwed up. In case you hadn&#8217;t heard, they issued a certificate for google.com (Google!) to somebody other than Google, and apparently that certificate was in fact used to compromise users in Iran.<\/p>\n<p>This is not exactly the first time a high-profile case like this happens, and who knows how many not-so-high profile cases happen that we never hear about.<\/p>\n<p>You might think that these kinds of things just happen, and there&#8217;s little anybody can do about it. Well, no, and it is scandalous that this industry of ours hasn&#8217;t fixed the problem yet. The problem is that we rely on certificate authorities when there is no earthly reason that we should. And that all the browser manufacturers hard-code that reliance into their browsers and don&#8217;t offer any better options.<\/p>\n<p>To <a href=\"http:\/\/www.waterken.com\/dev\/YURL\/Schneier\/\">quote<\/a> Bruce Schneier, about as much of an authority on security as anybody:<\/p>\n<blockquote><p>Digital             certificates provide no actual security for electronic commerce; it&#8217;s a             complete sham.<\/p><\/blockquote>\n<p>Repeat after me: Sham. Why again do we have them? So somebody can easily impersonate Google to Iranian internet users? Sometimes you&#8217;ve got to be wondering &#8230;<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Yet another case this week where unsuspecting users were compromised because a certificate authority that they had never heard of screwed up. In case you hadn&#8217;t heard, they issued a certificate for google.com (Google!) to somebody other than Google, and apparently that certificate was in fact used to compromise users in Iran. This is not&hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"webmentions_disabled":false,"footnotes":""},"categories":[59,35],"tags":[203,202,200,201],"class_list":["post-830","post","type-post","status-publish","format-standard","hentry","category-comments","category-security","tag-ca","tag-certificate","tag-diginotar","tag-ssl","kind-"],"kind":false,"_links":{"self":[{"href":"https:\/\/upon2020.com\/blog\/wp-json\/wp\/v2\/posts\/830","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/upon2020.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/upon2020.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/upon2020.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/upon2020.com\/blog\/wp-json\/wp\/v2\/comments?post=830"}],"version-history":[{"count":3,"href":"https:\/\/upon2020.com\/blog\/wp-json\/wp\/v2\/posts\/830\/revisions"}],"predecessor-version":[{"id":834,"href":"https:\/\/upon2020.com\/blog\/wp-json\/wp\/v2\/posts\/830\/revisions\/834"}],"wp:attachment":[{"href":"https:\/\/upon2020.com\/blog\/wp-json\/wp\/v2\/media?parent=830"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/upon2020.com\/blog\/wp-json\/wp\/v2\/categories?post=830"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/upon2020.com\/blog\/wp-json\/wp\/v2\/tags?post=830"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}