Skip to main content

Google Proposes Innovative SSL Security

posted onNovember 30, 2011
by l33tdawg

Google security researchers Ben Laurie and Adam Langley propose a new way in which digital certificates are issued and verified, to make sure that situations in which CAs issue them unknowingly will become rare or even inexistent.

In a paper called “Certificate Authority Transparency and Auditability,” Laurey and Langley state that another important objective is to make sure that users are protected against unlawfully issued certificates.

The method they propose is pretty straightforward and simple, but its deployment will be difficult, especially if others don’t cooperate. “Firstly, every publicly visible certificate should be published in a publicly auditable certificate log. Secondly, each certificate issued must be accompanied by an audit proof. Thirdly, servers must send these proofs along with the certificates to browsers, and browsers must check them,” reveals the paper.

Source

Tags

Google Security

You May Also Like

Recent News

Tuesday, November 19th

Friday, November 8th

Friday, November 1st

Tuesday, July 9th

Wednesday, July 3rd

Friday, June 28th

Thursday, June 27th

Thursday, June 13th

Wednesday, June 12th

Tuesday, June 11th