SSL is dead

Via Slashdot, phishers are using valid SSL certificates. SSL isn’t particularly strong crypto, and much of it’s value proposition comes from the fact that the issuers do some checking to make sure the applicant is who they say they are.

This is a stark illustration that identity has nothing to do with malicious intent. Or that the SSL certificate authorities are asleep at the wheel.

2 Responses to “SSL is dead”

  1. uid_zero Says:

    Since the signing CA is easily visible, any CA caught signing certs for known phishers should be publicly flogged. Or at least blacklisted.

  2. Ian Eure Says:

    I sure hope so.

Leave a Reply