Certificate Transparency.
The article offers the author's view on transparency among certificate authorities (CAs). He mentions an HTTPS certificate issued by Vasco Data Security International Inc.'s subsidiary DigiNotar BV which was applied for a man-in-the-middle assault to users in Iran. He notes that the attack has led t...
| Published in: | Communications of the ACM Vol. 57; no. 10; pp. 40 - 47 |
|---|---|
| Main Author: | |
| Format: | Article |
| Published: |
Association for Computing Machinery
Oct2014
|
| Subjects: | |
| Online Access: | View this record in EBSCOhost |
| fields | @attributes: recordID: 1 pdfLink: plink: https://search.ebscohost.com/login.aspx?direct=true&db=hlh&AN=98604808&site=ehost-live header: @attributes: shortDbName: hlh uiTerm: 98604808 longDbName: Humanities International Complete uiTag: AN controlInfo: bkinfo: jinfo: jid: 00010782 ACM jtl: Communications of the ACM issn: 00010782 maglogo: N pubinfo: dt: Oct2014 vid: 57 iid: 10 pid: 68 pub: Association for Computing Machinery artinfo: ui: 98604808 10.1145/2659897 ppf: 40 ppct: 7 formats: tig: atl: Certificate Transparency. aug: au: LAURIE, BEN affil: Founding director, The Apache Software Foundation Core team member, OpenSSL Member, Shmoo Group Director, Open Rights Group Director of Security, The Bunker Secure Hosting Founder-member, FreeBMD Visiting Fellow, Cambridge University’s Computer Laboratory Committer, FreeBSD Google, London su: Certificate authority DigiNotar BV OneSpan Inc. HTTP (Computer network protocol) Data security failures Bankruptcy Internet domain names Cyberterrorism Iran sug: subj: Iran Certificate authority DigiNotar BV OneSpan Inc. HTTP (Computer network protocol) Data security failures Bankruptcy Internet domain names Cyberterrorism ab: The article offers the author's view on transparency among certificate authorities (CAs). He mentions an HTTPS certificate issued by Vasco Data Security International Inc.'s subsidiary DigiNotar BV which was applied for a man-in-the-middle assault to users in Iran. He notes that the attack has led to the bankruptcy of the company along with claims of its poor security. He also points out the solution for addressing the issue which involve third parties that guarantee for the adherence between private keys and domain names. pubtype: Periodical doctype: Article src: R language: English refInfo: copyright: @attributes: flag: Y dt: @attributes: year: 2014 holdings: @attributes: islocal: N |
|---|