Date: Fri, 10 Oct 2014 12:37:28 -0400 From: Daniel Kahn Gillmor <dkg@...thhorseman.net> To: David Leon Gil <coruus@...il.com>, kristian.fiskerstrand@...ptuouscapital.com CC: oss-security@...ts.openwall.com, "gnupg-devel@...pg.org" <gnupg-devel@...pg.org>, Werner Koch <wk@...pg.org>, thijs@...ian.org Subject: Re: Re: 0xdeadbeef comes of age: making keysteak with GnuPG On 10/10/2014 12:23 PM, Daniel Kahn Gillmor wrote: > On 10/10/2014 12:01 PM, David Leon Gil wrote: >> > (While I know that if a root CA were caught intentionally issuing an >> > MitM cert for keybase.io or pgp.mit.edu would face likely >> > delisting/bankruptcy.) > I'd like to believe that also, but i think that some of the members of > the CA cartel might be "too big to fail" in the current infrastructure. > There's no chance that the CA will go bankrupt if they aren't delisted > (since the CA market is a lemon market), and every web site certified by > the bigger CAs has an incentive to argue against that CAs' delisting > (because it will break their web site). And, even when we can burn a small CA, the larger organization often carries on unharmed: http://www.links.org/?p=1268 --dkg Download attachment "signature.asc" of type "application/pgp-signature" (950 bytes)
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.