[OpenID] OpenID/Debian PRNG/DNS Cache poisoning advisory
Dick Hardt
dick at sxip.com
Fri Aug 8 17:29:24 UTC 2008
On 8-Aug-08, at 10:11 AM, Ben Laurie wrote:
>
> It also only fixes this single type of key compromise. Surely it is
> time to stop ignoring CRLs before something more serious goes wrong?
Clearly many implementors have chosen to *knowingly* ignore CRLs
despite the security implications, so my take away would be that the
current public key infrastructure is flawed.
-- Dick
More information about the general
mailing list