Skip to content

Comment on VeriSign hit by hackersparent

Comments

Well, how do you distribute trust? Do you have a quorum or something?

Consider this ... what if I wanted to introduce doubt that X is really verified, and thereby hurt their business. How can you avoid me doing stuff like that? Besides harsh laws of course.

> Well, how do you distribute trust? Do you have a quorum or something?

Basically, yes.

> Consider this ... what if I wanted to introduce doubt that X is really verified, and thereby hurt their business. How can you avoid me doing stuff like that? Besides harsh laws of course.

By not trusting you.

Right now, what happens is the browser and/or OS vendor determines a set of certificate authorities to declare "trusted", and all certificates they issue are simply assumed to be valid.

Instead, we could require, say, three signatures, each from different authorities, to invoke the normal "this is a secure connection to a properly-identified website" behavior.

But each of those authorities was still determined by the vendor to be trustworthy. It's still going to be the likes of e.g. VeriSign, Comodo, StartSSL, etc.. It's not going to be you.

But what if Verisign really doesn't like Bank of America, can they cast doubt on their websites now?

No, but if they could and did, their business would come to an abrupt end when browsers stopped trusting them anyway.

What if everyone did it to some company

That is in no way different than the current situation. If all of the dozens of trusted certificate authorities the world over has decided that they shouldn't provide certs for company X, you should probably be looking to company X for the problem, rather than the authorities.

In any case, users have always had the option of modifying the trust infrastructure or even ignoring it entirely.

Let me rephrase. What if every cert authority might do it to some company (different companies for different cert authorities)

How would you even know if they did?

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.