[cap-talk] Compelled Certificate Creation Attack on SSL

Raoul Duke raould at gmail.com
Fri Apr 23 11:38:45 PDT 2010


On Fri, Apr 23, 2010 at 11:29 AM, Jonathan S. Shapiro <shap at eros-os.org> wrote:
> The problem with centralizing trust is that (a) it's only a matter of
> time before any given source is compromised, and (b) when it is, the
> loss multipliers get pretty big...

apparently, some people/orgs see that not so much as a problem as a feature. :-(


More information about the cap-talk mailing list