lists.nanog.org
Sign In
Sign Up
Manage this list
Sign In
Sign Up
×
Keyboard Shortcuts
Thread View
j
: Next unread message
k
: Previous unread message
j a
: Jump to all threads
j l
: Jump to MailingList overview
Test
Thread
Start a new thread
Download
Threads by
month
----- 2025 -----
October
September
August
July
June
May
April
March
February
January
----- 2024 -----
December
November
October
September
August
July
June
May
April
March
February
January
----- 2023 -----
December
November
October
September
August
July
June
May
April
March
February
January
----- 2022 -----
December
November
October
September
August
July
June
May
April
March
February
January
----- 2021 -----
December
November
October
September
August
July
June
May
April
March
February
January
----- 2020 -----
December
November
October
September
August
July
June
May
April
March
February
January
----- 2019 -----
December
November
October
September
August
July
June
May
April
March
February
January
----- 2018 -----
December
November
October
September
August
July
June
May
April
March
February
January
----- 2017 -----
December
November
October
September
August
July
June
May
April
March
February
January
----- 2016 -----
December
November
October
September
August
July
June
May
April
March
February
January
----- 2015 -----
December
November
October
September
August
July
June
May
April
March
February
January
----- 2014 -----
December
November
October
September
August
July
June
May
April
March
February
January
----- 2013 -----
December
November
October
September
August
July
June
May
April
March
February
January
----- 2012 -----
December
November
October
September
August
July
June
May
April
March
February
January
----- 2011 -----
December
November
October
September
August
July
June
May
April
March
February
January
----- 2010 -----
December
November
October
September
August
July
June
May
April
March
February
January
----- 2009 -----
December
November
October
September
August
July
June
May
April
March
February
January
----- 2008 -----
December
November
October
September
August
July
June
May
April
March
February
January
----- 2007 -----
December
November
October
September
August
July
June
May
April
March
February
January
----- 2006 -----
December
November
October
September
August
July
June
May
April
March
February
January
----- 2005 -----
December
November
October
September
August
July
June
May
April
March
February
January
----- 2004 -----
December
November
October
September
August
July
June
May
April
March
February
January
----- 2003 -----
December
November
October
September
August
July
June
May
April
March
February
January
----- 2002 -----
December
November
October
September
August
July
June
May
April
March
February
January
----- 2001 -----
December
November
October
September
August
July
June
May
April
March
February
January
----- 2000 -----
December
November
October
September
August
July
June
May
April
March
February
January
----- 1999 -----
December
November
October
September
August
July
June
May
April
March
February
January
----- 1998 -----
December
November
October
September
August
July
June
May
April
March
February
January
----- 1997 -----
December
November
October
September
August
July
June
May
April
March
February
January
----- 1996 -----
December
November
October
September
August
July
June
May
April
March
February
January
----- 1995 -----
December
November
October
September
August
July
June
May
April
March
February
January
----- 1994 -----
December
November
October
September
August
July
June
May
April
March
February
January
----- 1993 -----
December
November
October
September
August
July
June
May
April
March
February
January
----- 1992 -----
December
November
October
September
August
July
June
May
April
March
February
January
test@lists.nanog.org
September 2025
1 participants
2 discussions
The state-level attack on the SSL CA security model
by Martin Millnert
09 Oct '25
09 Oct '25
To my surprise, I did not see a mention in this community of the latest proof of the complete failure of the SSL CA model to actually do what it is supposed to: provide security, rather than a false sense of security. Essentially a state somewhere between Iraq and Pakistan snatched valid certs for: -
mail.google.com
-
www.google.com
-
login.yahoo.com
-
login.skype.com
-
addons.mozilla.org
-
login.live.com
- "global trustee"
https://blog.torproject.org/blog/detecting-certificate-authority-compromiseā¦
http://www.comodo.com/Comodo-Fraud-Incident-2011-03-23.html
http://www.imperialviolet.org/2011/03/18/revocation.html
(on epic failure of cert revocation lists implementations in browsers, failing open (!))
http://blog.mozilla.com/security/2011/03/22/firefox-blocking-fraudulent-cerā¦
http://www.microsoft.com/technet/security/advisory/2524375.mspx
For over a week users of browsers, and the internet at large, were/was not informed by COMODO that their security was compromised. "Why not" is beyond many of us. Announcing this high and loud even before fixes were available would not have exposed more users to threats, but less. Conclusion: protecting people must not be a priority in the SSL CA model. In some places, failure of internet security means people die, and it is high time to start serious work to replace this time-and-time again proven flawed model with something that, at the very least, does not fail this tragically. DNSSEC is a good but insufficient start in this particular case. Regards, Martin
24
35
0
0
testing
by Bryan Fields
02 Oct '25
02 Oct '25
-- Bryan Fields 727-409-1194 - Voice
http://bryanfields.net
3
3
0
0
Results per page:
10
25
50
100
200