|
|
|
|
|
by tptacek
4436 days ago
|
|
First, "TOFU/POP" has a real name; it's "key continuity". Second, certificate pinning as implemented in Chrome doesn't depend directly on key continuity. Third, key continuity destroys the incentive to attack sites by compromising CAs, because even if you're hitting a site for the first time, many of the 10,000 other people hitting it from the same browser at around the same time aren't, and they'll detect the bogus cert. That only has to happen once for Google to put a gun to the rogue CA's temple. |
|
I am aware of both names, thank you.
>That only has to happen once for Google to put a gun to the rogue CA's temple.
Google can't really help in every single case. There are many situations where Google's revocation scheme can't keep up.
You also have to put a lot of trust in Google. You think Google is going to issue a revocation if they're under legal pressure not to?
As you are aware, human factors are frequently the weakest parts in a cryptosystem.