This is a discussion about cyberwarfare in a literal sense. The technical discussion shouldn't really be separated from the economic, political, social and human health concerns because all of those parts of the system interact deeply and directly. A goal of total political cooperation or submission leads to economic sanctions leading to serious human health effects leading to defensive denial of service attacks. Thi…
Announcing Keyless SSL
121–130 of 190 posts
Re: Announcing Keyless SSL
#122Earlier quoted context omitted.
Is it related? ;)
not really -- only in that they are both SSL-related. Free SSL is still in the works. More info soon-ish.
My money is on AOL as the CA[1].
[1] http://moderncrypto.org/mail-archive/messaging/2014/000618.h...
Re: Announcing Keyless SSL
#123Earlier quoted context omitted.
No disrespect meant, but from a security perspective the idea of patching security-critical software with a patch from a stranger on the Internet is kind of crazy, isn't it?
All open source software is made up of patches from strangers on the internet.
Re: Announcing Keyless SSL
#124After reading the beginning of the piece, I was expected something more...profound. Some deep mathematical breakthrough or something. Instead they separate the actual key signing, delegating it to the customer's device. That's nice and useful, but isn't quite what I was expecting.
"Tomorrow, we'll publish a full post on the nitty, gritty techical details of how, what has come to be called Keyless SSL™, works."
Re: Announcing Keyless SSL
#125Earlier quoted context omitted.
No disrespect meant, but from a security perspective the idea of patching security-critical software with a patch from a stranger on the Internet is kind of crazy, isn't it?
All open source software is made up of patches from strangers on the internet.
Re: Announcing Keyless SSL
#126isn't this completely missing the point, i.e. banks being able to say 'no third parties can see our clients identifying information/balances/etc?' yes, the SSL key doesn't leave the bank, but everything it is protecting is..
It only protects one thing - server identity. The best ciphers do you use DHE for negotiating the key, so the conversation between bank and the client is secure anyway.
Re: Announcing Keyless SSL
#127Re: Announcing Keyless SSL
#128Earlier quoted context omitted.
As Google and Yahoo will tell you after they found out the US government broke into their dedicated lines between data centers... No. It must be encrypted at every transfer without exception.
There's a huge difference between passively tapping a fiber optic cable and infiltrating a network to inject malicious traffic. All we've ever seen evidence of is NSA's passive tapping of Google & others.
Re: Announcing Keyless SSL
#129Re: Announcing Keyless SSL
#130Earlier quoted context omitted.
No disrespect meant, but from a security perspective the idea of patching security-critical software with a patch from a stranger on the Internet is kind of crazy, isn't it?
All open source software is made up of patches from strangers on the internet.