Sloppy certificate authorities put on notice

  • Thread starter Thread starter illumination
  • Start date Start date
Status
Not open for further replies.
I

illumination

Thread author
In the wake of GlobalSign, Comodo, and DigiNotar attacks, Microsoft, Mozilla, and Opera revoke untrustworthy certs...
Read More
 
There are a few problems with the certificate system.

One is that levels are only used on the certificate end ie:
Verisign has multiple levels of certificate authenticity but Windows doesn't actually care - they're all considered trusted.

The other is that that certs are used for UAC and UAC is flawed. You have certs from sites that may not be that amazing/compromised and as soon as they're used the application gets full access. It's a bit silly.

I like the cert system and I would definitely use it in a security model but the implementation is kinda lame.
 
Good explanation right there Hungry Man. Certificates are great for better security, But the way most companies utilizes it is sort of shameful.
 
Status
Not open for further replies.