Perimeter
10/18/2011
10:01 PM
Taher Elgamal
Taher Elgamal
Commentary
Connect Directly
RSS
E-Mail
50%
50%

On Trusting Certificate Authorities

The time has come for a way to vet CAs by reputation

I get questions almost daily about the weaknesses of the certificate authorities (CAs) that are today “trusted” in every browser. The decision we made years ago to use PKI as the cornerstone for security in SSL and the early Web is under attack because of the poor practices of some CAs and the fact that we could not tell or remove these from our trusted lists without patching the browsers.

We knew since the beginning that the trust model in browsers is not sufficient. Almost every online business now has some reputation elements that the Internet can help establish and inform the users. It is ironic that the businesses that are the core of the trust of the entire e-commerce world lack any reputation support.

It could be time for some Internet entity to start to collect reputation data on CAs, and serve users and other entities in that regard. As long as root keys are hard-coded into browsers, we are not able to revoke CAs, which is obviously a missing component of any PKI system. So, in the meantime, can we at least help the community?

Eventually, PKI implementations in browsers need to be revisited. Browser vendors are, in fact, the root of trust, regardless of opinions and business practices. And as such, it would have been so much easier for the browser to sign CA root keys instead of just hard-coding.

Recognized in the industry as the "inventor of SSL," Dr. Taher Elgamal led the SSL efforts at Netscape. He also wrote the SSL patent and promoted SSL as the Internet security standard within standard committees and the industry. Dr. Elgamal invented several industry and government standards in data security and digital signatures area, including the DSS government standard for digital signatures. In addition to serving on numerous corporate advisory boards, Dr. Elgamal is the Chief Security Officer at Axway, a global provider of multi-enterprise solutions and infrastructure. He holds a Ph.D. and M.S. in Computer Science from Stanford University. View more of his blog posts here.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Flash Poll
Current Issue
Cartoon
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-0640
Published: 2014-08-20
EMC RSA Archer GRC Platform 5.x before 5.5 SP1 allows remote authenticated users to bypass intended restrictions on resource access via unspecified vectors.

CVE-2014-0641
Published: 2014-08-20
Cross-site request forgery (CSRF) vulnerability in EMC RSA Archer GRC Platform 5.x before 5.5 SP1 allows remote attackers to hijack the authentication of arbitrary users.

CVE-2014-2505
Published: 2014-08-20
EMC RSA Archer GRC Platform 5.x before 5.5 SP1 allows remote attackers to trigger the download of arbitrary code, and consequently change the product's functionality, via unspecified vectors.

CVE-2014-2511
Published: 2014-08-20
Multiple cross-site scripting (XSS) vulnerabilities in EMC Documentum WebTop before 6.7 SP1 P28 and 6.7 SP2 before P14 allow remote attackers to inject arbitrary web script or HTML via the (1) startat or (2) entryId parameter.

CVE-2014-2515
Published: 2014-08-20
EMC Documentum D2 3.1 before P24, 3.1SP1 before P02, 4.0 before P11, 4.1 before P16, and 4.2 before P05 does not properly restrict tickets provided by D2GetAdminTicketMethod and D2RefreshCacheMethod, which allows remote authenticated users to gain privileges via a request for a superuser ticket.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Three interviews on critical embedded systems and security, recorded at Black Hat 2014 in Las Vegas.