EFF System To Warn of Certificate Breaches
snydeq writes "With its distributed SSL Observatory, the Electronic Frontier Foundation hopes to detect compromised certificate authorities and warn users about attacks, InfoWorld reports. 'The EEF, along with developers at the Tor Project and consulting firm iSec Partners, has updated its existing HTTPS Everywhere program with the ability to anonymously report every certificate encountered. The group will analyze the data so that it can detect any rogue certificates — and by extension, compromised authorities — its users encounter, says Peter Eckersley, technology projects director for the EFF.'"
Sounds really good on paper (or, for the literal ones here, on webpage), but we'll see how it works in practice. I hope it does what it hopes to do, but who knows?
"...the number of UNIX installations has grown to 10, with more expected..." - Dennis Ritchie/Ken Thompson, 1972
Some people don't know?
But only on Firefox.
Give me Classic Slashdot or give me death!
I know that abbreviation is long and complex, but since this article is mostly about them, can't you at least get it right in the summary?
Free unix account: freeshell.org
lol, now the certificate issuers need certificate issuers.
Yes. They defend everyone's rights, including hackers and including you.
"Here Lies Philip J. Fry, named for his uncle, to carry on his spirit"
The difference is that instead of issuing them, it will just copy them and verify them for others ...
So you get certdiff, which is useful, just like SSL certs themselves ... its useful right up until someone poisons the central authority.
Then what you do, is create another authority to watch the first authority who watches everyone elses authority so no one has any clue who is actually the authoritative source.
I see the idea, it has merit, but its just more of the same thing. You can't solve the problem by repeating the same non-functioning act over and over again. Its the definition of insanity you know.
Persistent Volume manager for Kubernetes - https://github.com/dwimsey/openshift-pvmanager
"Although this site's certificate is signed, and you approved the same certificate to be stored permanently about three years ago, the signing authority may have been compromised.
[Get me out of here] [I understand the risks, but fuck me with more dialogs because I need a refresher course in crypto]
[My name is Bruce Schneier; just show me the goddamned page]
[OK] [Cancel] [Apply] [Abort] [Revert] [Save]
Hopefully they have better follow-through on this than they did with TOSBack, which seems to have withered on the vine.
The Tor Project is heavily associated with Jacob Appelbaum, one of their core members and proponents (and also a major proponent of Wikileaks). Jacob was also part of the team that exploited the MD5 weakness of SSL and created their own rogue Certification Authority.
So at least they know what to look for. Information wants to be free, except when it doesn't.
Sup DAWG, we heard you like to verify trust so we put a certificate authority on your certificate authority so you can verify trust while you verify trust.
This "decentralized SSL Observatory" idea is fantastic. The notaries paradigm we've been discussing (Perspectives, Convergence) requires multiple views for efficacy, the more the better (within certain parameters). I'd been imagining a system in which individuals could opt to be notaries/cert reporters, and this is a step in that direction. Now the EFF could turn into a nexus for thousands and thousands of views. Of course they'd aggregate those thousands of views into a single point of failure, but that's okay, you'd only be using the EFF as one notary in your council of many. There are plenty of other trustworthy organizations who could run their own notaries based on similar methods or otherwise effective methods. I expect even individuals will run their own notaries, much as they run Tor servers or even NTP or SMTP.
I think Convergence is better. The EFF should put up their own notary and just join Convergence instead of having their own separate way of doing the same...
I have already switched and added a bunch of random notaries. Everyone can just self sign and the notaries do the rest. Man in the Middle? Most notaries will warn your data differs. If a notary sucks, kick it and add another. Simple and clean.
Artix
Your Linux, your init.
Why was post modded down? It shows SSL in Opera TLS 1.2, host can directly send you to a site concerned, and disabling javascript in Opera by site preferences prevents the latest attack in *beast* against SSL. The downmodder must have been the malware maker of the beast script I suspect who is upset that his script kiddie attack is useless against someone that knows what they're doing and is trying to bury it so others aren't made aware of how and why they can protect themselves versus it. The same poster did a better post today here on all of this which was very informative http://it.slashdot.org/comments.pl?sid=2439924&cid=37478006 [slashdot.org] in combination with what others there wrote in that conversation thread.