Certificate Transparency.

The article offers the author's view on transparency among certificate authorities (CAs). He mentions an HTTPS certificate issued by Vasco Data Security International Inc.'s subsidiary DigiNotar BV which was applied for a man-in-the-middle assault to users in Iran. He notes that the attack has led t...

Descripción completa

Detalles Bibliográficos
Publicado en:Communications of the ACM Vol. 57; no. 10; pp. 40 - 47
Autor principal: LAURIE, BEN
Formato: Artículo
Publicado: Association for Computing Machinery Oct2014
Materias:
Acceso en línea:Ver este registro en EBSCOhost
Descripción
Sumario:The article offers the author's view on transparency among certificate authorities (CAs). He mentions an HTTPS certificate issued by Vasco Data Security International Inc.'s subsidiary DigiNotar BV which was applied for a man-in-the-middle assault to users in Iran. He notes that the attack has led to the bankruptcy of the company along with claims of its poor security. He also points out the solution for addressing the issue which involve third parties that guarantee for the adherence between private keys and domain names.