Home / News I have a News Tip

Proposal on How SSL Certificate Industry Should Be Replaced Gains Some Momentum

Don't miss a thing – sign up for CircleID Weekly Wrap newsletter delivered to your inbox once a week.

SSL replacement proposal made by security expert Moxie Marlinspike, last August at the Black Hat Conference (called 'Convergence'), is gaining some momentum, particularly after the recent hacker attacks on DigiNotar, GlobalSign, Comodo and other SSL certificate authorities that have resulted in fake certificates coming into use on the web, including a fake Google certificate, since revoked. Marlinspike thinks this whole system — which props up the multi-million-dollar certificate authority business today — should be dumped in favor of the idea of the user more directly controlling how the browser trusts certificates based on so-called Convergence "notaries" proving online feedback about what to trust.

Read full story: Network World

Related topics: Cyberattack, Cybercrime, Cybersecurity

 
   

Comments

Two things David A. Ulevitch  –  Oct 12, 2011 11:48 AM PDT

This has been in the works for a LONG time, and discussed for a while.  SSL has always been a sham.  Momentum had been quietly building for a while, and it just took a few CAs to bring it into the mainstream light.  The idea of embedding SSL fingerprints in DNS has been discussed for years, for instance.

So my two thoughts:
1) This is definitely going to happen.  Chrome will be pushing it the Google way, and Moxie (and many others) will push it the other ways.  Both will probably gain traction.
2) This makes Verisign look very smart for selling off the SSL business to Symantec.  And makes Symantec look like the goofballs they usually are.  Their absolute lack of real security vision is second to none.

IETF DANE Paul Vixie  –  Oct 13, 2011 7:10 AM PDT

The certificate authority system used by the web's e-commerce system is indeed weak.  What's less certain is that it ought to be replaced by multiple approaches, one from Moxie, one from Google, and so on.

The Internet Engineering Task Force (IETF) has a DNS-based Authentication of Named Entities (DANE) working group and is a dozen revisions into a DNSSEC profile for authenticating the certificates needed for e-commerce.

This protocol will work, it will be as secure as DNSSEC itself, and it will scale.  I urge the technical and business communities to get behind a single global standard to replace the X.509 certificate authority system.

To post comments, please login or create an account.

Related Blogs

Related News

Explore Topics

Dig Deeper

Verisign

Cybersecurity

Sponsored by Verisign
Afilias

DNS Security

Sponsored by Afilias
Afilias Mobile & Web Services

Mobile Internet

Sponsored by Afilias Mobile & Web Services

Promoted Posts

Now Is the Time for .eco

.eco launches globally at 16:00 UTC on April 25, 2017, when domains will be available on a first-come, first-serve basis. .eco is for businesses, non-profits and people committed to positive change for the planet. See list of registrars offering .eco more»

Boston Ivy Gets Competitive With Its TLDs, Offers Registrars New Wholesale Pricing

With a mission to make its top-level domains available to the broadest market possible, Boston Ivy has permanently reduced its registration, renewal and transfer prices for .Broker, .Forex, .Markets and .Trading. more»

Industry Updates – Sponsored Posts

Attacks Decrease by 23 Precent in 1st Quarter While Peak Attack Sizes Increase: DDoS Trends Report

Leading Internet Associations Strengthen Cooperation

Verisign Releases Q4 2016 DDoS Trends Report: 167% Increase in Average Peak Attack from 2015 to 2016

Verisign Q3 2016 DDoS Trends Report: User Datagram Protocol (UDP) Flood Attacks Continue to Dominate

2016 U.S. Election: An Internet Forecast

Government Guidance for Email Authentication Has Arrived in USA and UK

ValiMail Raises $12M for Its Email Authentication Service

Don't Gamble With Your DNS

Defending Against Layer 7 DDoS Attacks

Understanding the Risks of the Dark Web

New TLD? Make Sure It's Secure

Verisign Releases Q2 2016 DDoS Trends Report - Layer 7 DDoS Attacks a Growing Trend

How Savvy DDoS Attackers Are Using DNSSEC Against Us

Facilitating a Trusted Web Space for Financial Service Professionals

MarkMonitor Partners with CYREN to Deepen Visibility into Global Phishing Attacks

Verisign Named to the Online Trust Alliance's 2016 Honor Roll

Verisign Q1 2016 DDoS Trends: Attack Activity Increases 111 Percent Year Over Year

Is Your TLD Threat Mitigation Strategy up to Scratch?

i2Coalition to Host First Ever Smarter Internet Forum

Encrypting Inbound and Outbound Email Connections with PowerMTA