This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org

Difference between revisions of "Talk:Certificate and Public Key Pinning"

From OWASP
Jump to: navigation, search
(Added failures)
 
Line 20: Line 20:
 
* CAs can become compromised
 
* CAs can become compromised
 
** http://isc.sans.edu/diary.html?storyid=11500
 
** http://isc.sans.edu/diary.html?storyid=11500
* Researchers can create Rogue CAs
+
* Researchers created Rogue CAs
 
** http://www.win.tue.nl/hashclash/rogue-ca/
 
** http://www.win.tue.nl/hashclash/rogue-ca/
 +
* Researchers collided certificates on existing CA certificates
 +
** http://www.win.tue.nl/~bdeweger/CollidingCertificates/ddl-full.pdf
 
* DNS can become compromised
 
* DNS can become compromised
 
** http://forums.theregister.co.uk/forum/2/2011/09/05/dns_hijack_service_updated/
 
** http://forums.theregister.co.uk/forum/2/2011/09/05/dns_hijack_service_updated/

Revision as of 07:52, 14 February 2013

Past Failures

This section is 'further reading' for those interested in surveying the landscape.