A world of hurt after GoDaddy, Apple, and Google misissue 1M certificates
1–10 of 143 posts
Re: A world of hurt after GoDaddy, Apple, and Google misissue 1M certificates
#2How true is this?
Re: A world of hurt after GoDaddy, Apple, and Google misissue 1M certificates
#3Curious why everyone doesn’t agree to use 64 bits in future and just let the mis-issued certs live out their natural life?
Seems to create a lot of busywork for lots of people for no discernible benefit?
Re: A world of hurt after GoDaddy, Apple, and Google misissue 1M certificates
#4“Almost no chance of exploitation.” How true is this?
2^63 and 2^64 are effectively the same cost to break. Instead of costing $2X to break, it now costs $X.
Re: A world of hurt after GoDaddy, Apple, and Google misissue 1M certificates
#5> it’s easy to think that a difference of 1 single bit would be largely inconsequential when considering numbers this big. In fact, he said, the difference between 263 and 264 is more than 9 quintillion.
Re: A world of hurt after GoDaddy, Apple, and Google misissue 1M certificates
#6Re: A world of hurt after GoDaddy, Apple, and Google misissue 1M certificates
#7Given that there seems to be no security impact (and none expected in the next year or two)... Curious why everyone doesn’t agree to use 64 bits in future and just let the mis-issued certs live out their natural life? Seems to create a lot of busywork for lots of people for no discernible benefit?
> 4) This only came up because of DarkMatter, a very shady operator who most people are very happy to have an excuse to screw with technicalities.
Edit maybe these are sources?
https://bugzilla.mozilla.org/show_bug.cgi?id=1531800
https://groups.google.com/forum/#!msg/mozilla.dev.security.p...
Still not getting the whole picture.
Re: A world of hurt after GoDaddy, Apple, and Google misissue 1M certificates
#8“Almost no chance of exploitation.” How true is this?
Re: A world of hurt after GoDaddy, Apple, and Google misissue 1M certificates
#9Okay, but, that's because 2^63 itself is more than 9 quintillion. Where the search space was previously 18 quintillion, it's now 9 quintillion. Both of those are "big". The attack is 50% easier than "theoretically impossible before certificate expiration," which should still mean that it's impossible.