Become a fan of Slashdot on Facebook

 



Forgot your password?
typodupeerror
×
Mozilla Security The Internet IT Technology

Mozilla Asks All CAs To Audit Security Systems 77

Trailrunner7 writes "Already having revoked trust in all of the root certificates issued by DigiNotar, Mozilla is taking steps to avoid having to repeat that process with any other certificate authority trusted by Firefox, asking all of the CAs involved in the root program to conduct audits of their PKIs and verify that two-factor authentication and other safeguards are in place to protect against the issuance of rogue certificates."
This discussion has been archived. No new comments can be posted.

Mozilla Asks All CAs To Audit Security Systems

Comments Filter:
  • by DarkFencer ( 260473 ) on Thursday September 08, 2011 @05:08PM (#37345206)

    It really is security theater now. I've had to get certs from various vendors for the .edu I work at. They need 'official' documents from 'someone important'. Like a letter on official looking letter head with a copy of a photo ID faxed to them. Yeah. Real secure. Lemme break out my copy of photoshop.

    How about at the very least the verifications some sites use to show that you control a domain? For example, the CA says that in order to verify 'somesystem.somewhere.com' we're going to need you to put this arbitrary string in a TXT record on your DNS server for that host.

    When setting up a domain on Google Apps or MS Live (or other places) they ask you to do this as one of the things to do to prove domain ownership. Yes - obviously if your DNS is owned this isn't a problem, but its a heck of a lot better than the process now.

  • by LordLimecat ( 1103839 ) on Thursday September 08, 2011 @05:12PM (#37345242)

    I was going to reply point by point to your complaints, but then I realized:
    A) youre an AC, and probably trolling, and know that if you posted under your real handle your karma would tank because..
    B) most of your complaints are garbage because...
    C) they have all been addressed before in about a zillion threads, and
    D) your entire post is off topic anyways.

  • by StripedCow ( 776465 ) on Thursday September 08, 2011 @05:21PM (#37345320)

    ...unless you submit yourself to an INDEPENDENT audit you will be revoked from our default trusted root certs

    In the case of Diginotar, Price Waterhouse Coopers was doing the audits.

An authority is a person who can tell you more about something than you really care to know.

Working...