Go Back   Wireless and Wifi Forums > News > Newsgroups > comp.security.misc
Register FAQ Forum Rules Members List Calendar Search Today's Posts Advertise Mark Forums Read

 
Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 03-28-2011, 11:07 AM
Gilles Ganault
Guest
 
Posts: n/a
Default [SSL] Comodo breach in plain English?

Hello

I'd like to understand what the recent breach at Comodo means in
plain English:

www.pcmag.com/article2/0,2817,2382518,00.asp

I only know that SSL is based on the two-key encryption method, where
the server sends its public key that the browser will use to encrypt a
session key that will be used to encrypt any HTTPS connection.

If I got it right, certificates are used to be positive that the
server the browser connects is indeed the right server, but I'm not
clear about how this part really works.

Could someone explain this in basic terms?

Thank you.

Reply With Quote
  #2 (permalink)  
Old 03-28-2011, 01:05 PM
Thor Kottelin
Guest
 
Posts: n/a
Default Re: [SSL] Comodo breach in plain English?

"Gilles Ganault" <nospam@nospam.com> wrote in message
news:dtq0p6950sb709bljt279k9vren05duf24@4ax.com...

> I'd like to understand what the recent breach at Comodo means in
> plain English


Certificate authorities are expected to follow their certification
policies to ensure that only Google can obtain a certificate for
www.google.com, Microsoft for live.com et cetera. This is a prerequisite
for trusting them.

In this incident, a security breach at a registration authority allowed an
attacker to issue fraudulent certificates that were nevertheless signed by
Comodo and could therefore have been used successfully to impersonate e.g.
www.google.com.

Comodo explains the incident at
http://www.comodo.com/Comodo-Fraud-I...011-03-23.html. Is there
something in particular you wonder about?

--
Thor Kottelin
http://www.anta.net/


Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT. The time now is 05:27 PM.



Powered by vBulletin® Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.6.0 PL2

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45