Errrmmm, I'm not entirely sure that's correct - I wonder how many of Sony's private keys are in scriptkiddies hands right now?
The webserver needs access to the private key. Anyone who gets root on the webserver can read the private key.
Errrmmm, I'm not entirely sure that's correct - I wonder how many of Sony's private keys are in scriptkiddies hands right now?
The webserver needs access to the private key. Anyone who gets root on the webserver can read the private key.
[1] http://www.thales-esecurity.com/Products/Hardware%20Security...
For example, let's say you collected a large amount of https traffic by listening in on wifi hotspots or such like, then you attacked a certificate authority and managed to gain access to everything they have. This would be very bad, but you wouldn't be able to decrypt the traffic you'd recorded because you still wouldn't have each of the private keys used. That's very different from the problem of RSA tokens. Gaining access to RSA's servers resulted in compromising every token. Decentralization is often key to security.