09.08.2015 Views

More Tricks For Defeating SSL In Practice

More Tricks For Defeating SSL In Practice

More Tricks For Defeating SSL In Practice

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Back <strong>In</strong> The Day●●●●Most CAs didn't explicitly set basicConstraints:CA=FalseWhether the field was there or not, most <strong>SSL</strong>implementations didn't bother to check it.Anyone with a valid leaf node certificate couldcreate and sign a leaf node certificate for anyother domain.When presented with a complete chain, IE,Outlook, Konqueror, Open<strong>SSL</strong>, and othersconsidered it valid...Moxie Marlinspike<strong>In</strong>stitute <strong>For</strong> Disruptive Studies

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!