View Single Post
  #1  
Old 01-11-2016, 18:03
Shub-Nigurrath's Avatar
Shub-Nigurrath Shub-Nigurrath is offline
VIP
 
Join Date: Mar 2004
Location: Obscure Kadath
Posts: 971
Rept. Given: 70
Rept. Rcvd 431 Times in 101 Posts
Thanks Given: 83
Thanks Rcvd at 405 Times in 127 Posts
Shub-Nigurrath Reputation: 400-499 Shub-Nigurrath Reputation: 400-499 Shub-Nigurrath Reputation: 400-499 Shub-Nigurrath Reputation: 400-499 Shub-Nigurrath Reputation: 400-499
Indeed for what concerns the rougue-CAs the best way is always to break what's existing and catch low hanging fruits. I mean, there are so many house-made CAs in enterprises (e.g., handling enterprise stores, VPNs, and so on) that are vulnerable, not enough protected or even not updated that it is enough for years ahead. Not speaking of certificates that can be stolen from the enterprise BYOD terminals..

These studies are extremely interesting, but are accademic exercises, meant to force CA producers/sw vendor to change default hash algos or crypto suites. The problems above instead, will stay, whatever hash algo you use :-)
__________________
Ŝħůb-Ňìĝùŕřaŧħ ₪)
There are only 10 types of people in the world: Those who understand binary, and those who don't
http://www.accessroot.com
Reply With Quote