Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
joshtalon
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
1.
▲
by
joshtalon
15y ago
> This reduces the MITM to the initial handshake. Mostly. No matter much you trim your certificate chain, there's nothing preventing Google/your bank/Amazon/etc from sharing their private key with, say, Uncle Sam. However, the backdoo
2.
▲
by
joshtalon
15y ago
Makes you wonder what actually happened with TrustWave (there's obviously more to it than "Oh, this was an ethical dilemma so we stopped."). Probably their customer found a way into the intermediate CA private key and was being naughty wit
3.
▲
by
joshtalon
15y ago
Chrome already has a mechanism to detect a MITM for Google's servers by embedding those servers' public keys into Chrome itself. Of course, that doesn't stop a company from placing locally-trusted rogue certificates on computers they contro
4.
▲
by
joshtalon
15y ago
They can do public-key pinning like Chrome does (for example, they embed the "mail.google.com" public key into Chrome itself, and verify that it's the certificate you're TLS'ing to.
5.
▲
by
joshtalon
15y ago
I can not understand why, in Microsoft's blog post, they posted a Quality 20% JPEG of their new logo ( http://windowsteamblog.com/cfs-filesystemfile.ashx/__key/Com... ). It's compressed so much that there's a slight green hue around the bl