BLU Discuss list archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Discuss] Why the dislike of X.509?
- Subject: [Discuss] Why the dislike of X.509?
- From: bogstad at pobox.com (Bill Bogstad)
- Date: Mon, 25 Aug 2014 17:28:01 -0400
- In-reply-to: <CAAbKA3UoGjuzruNgOHXQBNxXP5xkKk-drZEYfc+83HSpg6mxMg@mail.gmail.com>
- References: <53F9F6B9.4060505@stephenadler.com> <20140824161132.GE14848@randomstring.org> <be314521ab6bebb6add54d706b042f01.squirrel@mail.mohawksoft.com> <53FA1C3B.70908@gmail.com> <53FB19E5.4080602@aeminium.org> <53FB4A5D.2030305@gmail.com> <CA+h9Qs5GnC6d1ejBQC=crtHwxoDiFWo4Kn+xjt0eiA8Kr733_A@mail.gmail.com> <53FB70E6.50706@gmail.com> <CAAbKA3VMpFi37aJ2510XXUYLQu4qEMPYfhDWU6aBd9oXGnTcNw@mail.gmail.com> <023d694b896d29f060da27a977f040d4.squirrel@mail.mohawksoft.com> <CAAbKA3UoGjuzruNgOHXQBNxXP5xkKk-drZEYfc+83HSpg6mxMg@mail.gmail.com>
On Mon, Aug 25, 2014 at 3:54 PM, Bill Ricker <bill.n1vux at gmail.com> wrote: > ... > > (Which doesn't change that anything that smells like escrow smells > 'off' to those who care about security that really works. From what > Rich has said re dates, his allergy to escrow likely stems from the > same controversy as mine. > http://www.cryptomuseum.com/crypto/usa/clipper.htm > http://en.wikipedia.org/wiki/Clipper_chip#Backlash > X509 PKI is not normally considered an escrow regime in normal > usage, but Rich is quite correct that central CAs or other registries > have *abilities* that are hard to distinguish from Escrow - even if > they never know your private key, they can at the very least forge > another one with the same apparent identity, and so spoof you to > others -- or spoof someone important to you. > I think there are still some significant differences between key escrow and a X509 PKI system. Please correct any errors. Key Escrow - Holder of Key can read all your old messages, read any new messages you create, and pretend to be you in a way that is indistinguishable? from your own signing. X509 PKI - Holder of a CA can't read old messages you sent, can't read any new messages that you send, can pretend to be you (but with a key that is different from the one that you are using). The pretending to be you is a bit like the you/evil twin thing. Recipient can't tell which one is the real you, but can tell that two different entities are trying to claim to be you based on the CA that they are using. (Okay if they compromised the CA that you actually used, that may not be true; but lets assume they compromised Certs-R-Us instead of whatever ultra-secure CA that you used.) Now while I see that PKI has issues, I think it is a little much to claim that it is as bad as PKI. Or maybe I'm missing something. Bill Bogstad
- Follow-Ups:
- [Discuss] Why the dislike of X.509?
- From: bill.n1vux at gmail.com (Bill Ricker)
- [Discuss] Why the dislike of X.509?
- References:
- [Discuss] vnc
- From: adler at stephenadler.com (Stephen Adler)
- [Discuss] vnc
- From: dsr at randomstring.org (Dan Ritter)
- [Discuss] vnc
- From: markw at mohawksoft.com (markw at mohawksoft.com)
- [Discuss] vnc
- From: richard.pieri at gmail.com (Richard Pieri)
- [Discuss] vnc
- From: nuno at aeminium.org (Nuno Sucena Almeida)
- [Discuss] Why the dislike of X.509?
- From: richard.pieri at gmail.com (Richard Pieri)
- [Discuss] Why the dislike of X.509?
- From: jabr at blu.org (John Abreau)
- [Discuss] Why the dislike of X.509?
- From: richard.pieri at gmail.com (Richard Pieri)
- [Discuss] Why the dislike of X.509?
- From: bill.n1vux at gmail.com (Bill Ricker)
- [Discuss] Why the dislike of X.509?
- From: markw at mohawksoft.com (markw at mohawksoft.com)
- [Discuss] Why the dislike of X.509?
- From: bill.n1vux at gmail.com (Bill Ricker)
- [Discuss] vnc
- Prev by Date: [Discuss] Why the dislike of X.509?
- Next by Date: [Discuss] Why the dislike of X.509?
- Previous by thread: [Discuss] Why the dislike of X.509?
- Next by thread: [Discuss] Why the dislike of X.509?
- Index(es):