How secure is HTTPS today? How often is it attacked? (2011)
eff.org
eff.org
This technology needs to be improved. Encrypted and authenticated HTTP connection should be a default not a premium feature that site owners need to pay for.
Why wild card certs are so much more expensive than single domain certs? From CA's infrastructure and verification point of view there shouldn't be any additional cost associated with issuing a wild card cert.
A better solution would be to tie all DNS records to a key on a hardware device that can be in the actual hands of the website operator (in a safe). What users want to know is that the website they visited yesterday is the one they visited today. Physical security of a single key that is never allowed to change is a better way to guarantee that than key chains.
What you describe is basically a self-signed certificate which is known to be a poor solution. It easily allows someone to consistently MITM the whole web (think great firewall of china) without the users knowing.
https://www.eff.org/files/colour_map_of_CAs.pdf
Even the very small university I went to (their organization is terrible by the way) is a certificate authority. How is that even possible?
They all are "trusted" by the DNF which is the German Research Network.
"Science itself organized the German National Research and Education Network, DFN, the communications network for science and research in Germany. It connects universities and research institutions with one another and has become an integral part of the European and worldwide community of research and education networks."
Quote:
"Break into any Certificate Authority (or compromise the web applications that feed into it). As we learned from the SSL Observatory project, there are 600+ Certificate Authorities that your browser will trust; the attacker only needs to find one of those 600 that she is capable of breaking into."
certificate pinning is already in Chrome, and I think ChannelID is coming soon (if not already).
ChannelID: http://tools.ietf.org/html/draft-balfanz-tls-channelid-00
[1] https://code.google.com/p/chromium/issues/detail?id=136462#c...
> There are four classes of attackers against which we consider our security guarantees: passive network attackers, active network attackers, active network attackers with misissued certificates and attackers in possession of the legitimate server's private key.
Basically (and this is just my understanding), it should mean a MITM cannot decode the encrypted stream even if he has the legitimate server's private key.
(Disclosure: I wrote that section of the draft.)
ChannelID seems to operate in the same fashion. The first connection from Client->Server is completely without any security, but further connections can be verified.