Earlier quoted context omitted.
You'd still need some kind of software support to trigger the exploit. At which point you may as well go with a software-only attack.
Naah, if it's simply a few added instructions I agree with you. But let's think in a wider scope (disclaimer: this is not my idea, I remember reading about it a long time ago): what if a certain cryptographic "magic code" at the beginning of a memory page would trigger the execution of arbitrary code embedded in that page? Such a thing could be triggered over the network, wireless through bluetooth/wifi, or by specia…
Http://www.google.com/wo0dh3ad
21–30 of 37 posts
Re: Http://www.google.com/wo0dh3ad
#22http://advocacy.globalvoicesonline.org/2011/01/07/tunisia-bl...
Re: Http://www.google.com/wo0dh3ad
#23Re: Http://www.google.com/wo0dh3ad
#24So, is pornography actually illegal in Tunisia, or is this a case of "Well, we just don't like it when you do it."?
Re: Http://www.google.com/wo0dh3ad
#25Earlier quoted context omitted.
I guess SSL is an improvement. Now you just have to trust 2000 companies and anyone controlling their purse strings, instead of having to trust everyone. You feel safe, which is much better than being safe...
So what you are trying to convey, there is no advantage to using SSL vs. plain connection? I wonder why then they shut down SSL in my home country during elections..
Re: Http://www.google.com/wo0dh3ad
#26Earlier quoted context omitted.
So what you are trying to convey, there is no advantage to using SSL vs. plain connection? I wonder why then they shut down SSL in my home country during elections..
There's no advantage against a motivated, state-sized actor. Against other attackers there is still substantial advantage.
Re: Http://www.google.com/wo0dh3ad
#27Earlier quoted context omitted.
There's no advantage against a motivated, state-sized actor. Against other attackers there is still substantial advantage.
Let's say there is no advantage against (maybe) the U.S. government. I fail to see how any other state or entity would be able to manipulate certificate authority chain in general.
Re: Http://www.google.com/wo0dh3ad
#28Earlier quoted context omitted.
Naah, if it's simply a few added instructions I agree with you. But let's think in a wider scope (disclaimer: this is not my idea, I remember reading about it a long time ago): what if a certain cryptographic "magic code" at the beginning of a memory page would trigger the execution of arbitrary code embedded in that page? Such a thing could be triggered over the network, wireless through bluetooth/wifi, or by specia…
Stuff like this would be easy to hide in the guise of "Hardware DRM."
It'd be mighty interesting to tear apart / scan / reverse engineer some modern CPUs like they did with the 6502. Then again, these beasts are so complex that's similar to looking for a needle in a galaxy-sized haystack.
Re: Http://www.google.com/wo0dh3ad
#29Earlier quoted context omitted.
Let's say there is no advantage against (maybe) the U.S. government. I fail to see how any other state or entity would be able to manipulate certificate authority chain in general.
If you are a certificate authority, you can issue certificates for any domain. There is nothing in the technology preventing you from issuing a whitehouse.gov certificate merely because you are based in Iran, for example.
Re: Http://www.google.com/wo0dh3ad
#30Earlier quoted context omitted.
If you are a certificate authority, you can issue certificates for any domain. There is nothing in the technology preventing you from issuing a whitehouse.gov certificate merely because you are based in Iran, for example.
Who is going to sign it?
If you mean the certificates that the certificate authority issues, then the certificate authority signs them itself.
If you mean who signs the certificate authority's authority certificate, then either another certificate authority signs it, or the certificate authority signs it itself and pays the browser makers to include it as a root certificate in their browsers.
I'm not sure what you're trying to get at?