Friday, July 22, 2011

Certificate authority

Comment:

What if the certificate authority discloses private information of users? Safe?

Follow-up:

Yes it is definitely possible that a CA could inadvertently discloses some private information. For example, a CA’s database could be compromised by some hackers, just like the credit-card numbers are disclosed in some hacking of e-business Web sites.

So in a sense, one could argue that our Internet security is quite fragile.

Comment:

Who will certify the public key of the certificate authority?

Follow-up:

A CA’s public key is not “certified” but just published in a widely accessible site so that everyone can verify it.

1 comment:

  1. Nice post. Thanks for explaining the meaning of certificate authority and sharing this important point. If there's possibility that CA's database could be compromised by some hackers then how people can rely on them.
    digital certificate

    ReplyDelete