Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Google is actually quite diligent in this regard and have caught CAs with their pants down in the past.

They're taking it a step further and using certificate pinning in Chrome to catch MITM attacks in real time across a large portion of the internet. http://blog.chromium.org/2011/06/new-chromium-security-featu...

It's not scalable at all, but cuts out a large attack vector for a lot of communications. It wouldn't take a ton of pinned certificates to make a big dent in these NSA programs--really just look at the logos and make sure that each has their certificates pinned.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: