Boston Linux & UNIX was originally founded in 1994 as part of The Boston Computer Society. We meet on the third Wednesday of each month, online, via Jitsi Meet.

BLU Discuss list archive


[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[Discuss] Why the dislike of X.509?



On Mon, Aug 25, 2014 at 3:55 PM,  <markw at mohawksoft.com> wrote:
> No security can withstand privileged access.

Yes.
But anything with key escrow - or its moral equivalents - is
vulnerable in more ways, creates more trouble for adjacent systems.

Compartmentalization vs Centralization.
Ease of use vs Ease of Administration vs Security.
Eternal tensions.

Worse, key escrow or PKI CA makes the illicit privileged accessors
able to leave rather impressive false evidence against whomever they
want. If I break into a system rich has access and create a duplicate
key for 'rpieri', I can then access the system remotely as him, and
it's him in all the logs, without having to


-- 
Bill Ricker
bill.n1vux at gmail.com
https://www.linkedin.com/in/n1vux



BLU is a member of BostonUserGroups
BLU is a member of BostonUserGroups
We also thank MIT for the use of their facilities.

Valid HTML 4.01! Valid CSS!



Boston Linux & Unix / webmaster@blu.org