Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » Comodo continues to issue certificates to known Malware
Search Topic:
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
Anyone have a similar problem? »
« 2nd vulnerability in Firefox 3.0.10: KEYGEN tag  
AuthorAll Replies


danny9
Go Ahead, Make My Day
Premium
join:2002-07-14
Clinton Township, MI
clubs:
reply to hayc59
Re: Comodo continues to issue certificates to known Malware

Do you know if Comodo is the only one doing this or if it is a common practice among other vendors?
Just curious.
--
VoicePulse 07/29/04


ColdinCbus
Premium
join:2002-12-28
Columbus, OH
clubs:

Other SSL Cert providers are doing the same thing. The issue is that Comodo also has a security product software line where the other cert providers don't.
--
Team Discovery Project Hope


coldmoon
Premium
join:2002-02-04
Broadway, NC
·Windstream

said by ColdinCbus See Profile :

Other SSL Cert providers are doing the same thing. The issue is that Comodo also has a security product software line where the other cert providers don't.
This complicates things I am sure, but does not always mean that the commercial services "division" is set up to support or coordinate with the PC security side of things. While on a personal note I would suggest strongly that this should be tighter, there is no obligation on the part of a company to follow a specific business or operational model.

The litmus test here is what the competition will do and whether taking an opposing approach to the current models will result in:

1. Greater market share
2. A realignment of the certificate industry that focuses on real security

What is important now is that this is being debated and exposed to a wider audience. At the very least it should give competitors something to think about...

JMHO
Mike
--
Returnil - 21st Century body armor for your PC


ColdinCbus
Premium
join:2002-12-28
Columbus, OH
clubs:


1 edit
I totally agree with you. What I would like to see is that Comodo, at least, run the process through a database of rouge domains and IP addresses (I am pretty sure they are plugged into the same matrix we are if not even deeper in so they should have access to a pretty healthy list). That should flag some of the certificates for manual review. IT would be a step in the right direction for "Creating Trust Online".
--
Team Discovery Project Hope
-
Forums » Up and Running » Security » SecurityAnyone have a similar problem? »
« 2nd vulnerability in Firefox 3.0.10: KEYGEN tag  


Thursday, 10-Dec 02:56:53 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [200] Sprint Sued For Distracted Driving Death
· [116] AT&T Launching New 24 Mbps U-Verse Tier
· [82] 3G Network Test Says AT&T Is Tops
· [72] Mediacom Unveils 105 Mbps Pricing
· [66] Sprint Poised For A Turnaround?
· [66] WPA Cracker: Test WPA-PSK Networks In 20 Minutes
· [66] AT&T Hints At Usage-Based iPhone Data Pricing
· [51] The Future Of Wi-Fi Is Bright
· [47] Site Leaks Yahoo, Verizon Fed Data Share Pricing
· [45] Microwaving Your Innards Is Not 'Extreme'
Most people now reading
· Cross Server Dungeon Experience [World of Warcraft]
· The aftermath [World of Warcraft]
· ICC strats [World of Warcraft]
· Adobe Flash Player version 10.0.42.34 [Security]
· [ Classes] Druid tanking: rotation and glyphs [World of Warcraft]
· Windows 7 boot manager editing questions [Microsoft Help]
· 3.x Feral Druid - Bear Tanking Guide [World of Warcraft]
· It's happening again [AT&T Southwest]
· Official "Invite" thread Part 3 - ALL INVITES GO HERE ! [Filesharing Software]
· [How to] Install Asterisk on an Asus WL-520GU router [VOIP Tech Chat]