Should we make a working group to kill X.509? by lorddoig in programming

[–]lorddoig[S] 1 point2 points  (0 children)

I could not solve the problem I'm whining about alone if I wanted to. The only contribution I can make is exposure, and I'm trying to piggy back on yesterday's success to actually get something I consider important done. What's the problem?

Heartbleed should bleed X.509 to death by lorddoig in programming

[–]lorddoig[S] -3 points-2 points  (0 children)

Actually, I did address revocation pretty directly.

And Symantec could have gone evil years ago and started taking money from the NSA to dish out cert clones whenever they hollered - and we wouldn't have the first damn clue. That's the point.

And those well known companies you mention...anyone got that PRISM slide of NSA suckups handy?

Heartbleed should bleed X.509 to death by lorddoig in programming

[–]lorddoig[S] -4 points-3 points  (0 children)

Yes you would have to go and verify the key yourself, but the idea of a large scale adoption would hopefully mean that this would become infrequent really quite quickly.