Create an Account
username: password:
 
  MemeStreams Logo

Certi fied Lies: Detecting and Defeating Government Interception Attacks Against SSL

search

Decius
Picture of Decius
Decius's Pics
My Blog
My Profile
My Audience
My Sources
Send Me a Message

sponsored links

Decius's topics
Arts
  Literature
   Sci-Fi/Fantasy Literature
  Movies
   Sci-Fi/Fantasy Films
  Music
   Electronic Music
Business
  Finance & Accounting
  Tech Industry
  Telecom Industry
  Management
  Markets & Investing
Games
Health and Wellness
Home and Garden
  Parenting
Miscellaneous
  Humor
  MemeStreams
Current Events
  War on Terrorism
Recreation
  Cars and Trucks
  Travel
Local Information
  United States
   SF Bay Area
    SF Bay Area News
Science
  Biology
  History
  Math
  Nano Tech
  Physics
Society
  Economics
  Politics and Law
   Civil Liberties
    Internet Civil Liberties
    Surveillance
   Intellectual Property
  Media
   Blogging
Sports
Technology
  Computer Security
  Macintosh
  Spam
  High Tech Developments

support us

Get MemeStreams Stuff!


 
Certi fied Lies: Detecting and Defeating Government Interception Attacks Against SSL
Topic: Miscellaneous 5:36 pm EDT, Apr 11, 2011

This paper introduces the compelled cer-
ti cate creation attack, in which government
agencies may compel a certi cate authority to
issue false SSL certi cates that can be used by
intelligence agencies to covertly intercept and
hijack individuals' secure Web-based commu-
nications. Although we do not have direct ev-
idence that this form of active surveillance is
taking place in the wild, we show how prod-
ucts already on the market are geared and mar-
keted towards this kind of use|suggesting such
attacks may occur in the future, if they are
not already occurring. Finally, we introduce
a lightweight browser add-on that detects and
thwarts such attacks.

Certi fied Lies: Detecting and Defeating Government Interception Attacks Against SSL



 
 
Powered By Industrial Memetics
RSS2.0