View Single Post
  #1   (View Single Post)  
Old 17th November 2011
J65nko J65nko is offline
Administrator
 
Join Date: May 2008
Location: Budel - the Netherlands
Posts: 4,131
Default Certificate fraud: Protection against future "DigiNotars"

From http://h-online.com/-1380288

Quote:
To better protect content providers against the distribution of bogus certificates, an HTTP header extension containing a fingerprint of their certificates has been proposed. This approach, which has been partly tested in Chrome, was presented by Ian Fette, Google Senior Product Manager, at a meeting of the Internet Engineering Task Force (IETF) in Taipei. Chrome users were able to detect the bogus DigiNotar certificates because Chrome had embedded the hashes of valid Google certificates.
__________________
You don't need to be a genius to debug a pf.conf firewall ruleset, you just need the guts to run tcpdump
Reply With Quote