Google Proposes Innovative SSL Security
Google security researchers Ben Laurie and Adam Langley propose a new way in which digital certificates are issued and verified, to make sure that situations in which CAs issue them unknowingly will become rare or even inexistent.
In a paper called “Certificate Authority Transparency and Auditability,” Laurey and Langley state that another important objective is to make sure that users are protected against unlawfully issued certificates.
The method they propose is pretty straightforward and simple, but its deployment will be difficult, especially if others don’t cooperate. “Firstly, every publicly visible certificate should be published in a publicly auditable certificate log. Secondly, each certificate issued must be accompanied by an audit proof. Thirdly, servers must send these proofs along with the certificates to browsers, and browsers must check them,” reveals the paper.