Sloppy certificate authorities put on notice

Status
Not open for further replies.
I

illumination

Thread author
In the wake of GlobalSign, Comodo, and DigiNotar attacks, Microsoft, Mozilla, and Opera revoke untrustworthy certs...
Read More
 

Hungry Man

New Member
Jul 21, 2011
669
There are a few problems with the certificate system.

One is that levels are only used on the certificate end ie:
Verisign has multiple levels of certificate authenticity but Windows doesn't actually care - they're all considered trusted.

The other is that that certs are used for UAC and UAC is flawed. You have certs from sites that may not be that amazing/compromised and as soon as they're used the application gets full access. It's a bit silly.

I like the cert system and I would definitely use it in a security model but the implementation is kinda lame.
 

moonshine

Level 7
Verified
Apr 19, 2011
1,264
Good explanation right there Hungry Man. Certificates are great for better security, But the way most companies utilizes it is sort of shameful.
 
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top