Search Mailing List Archives

Limit search to: Subject & Body Subject Author
Sort by: Reverse Sort
Limit to: All This Week Last Week This Month Last Month
Select Date Range     through    

[liberationtech] How to protect users from compelled fake ssl certs?

Daniel Sieradski ds at
Wed Jul 3 11:54:30 PDT 2013

i use to verify certs on the client end to make sure i'm not being man in the middled. it would be awesome if this were available as a firefox and chrome plugin that automatically did a check for you and gave you a red or green light.

Daniel Sieradski
ds at

Follow me at
Public key

On Jul 3, 2013, at 2:41 PM, coderman <coderman at> wrote:

> On Tue, Jul 2, 2013 at 10:01 AM, Ralph Holz <holz at> wrote:
>>> DANE:
>>> CAA:
>>> ....
>> I wonder whether that would have protected against the Comodo Hacker. It
>> seems it depends when and from where the CAA checks are run.
> it would not. Comodo Hacker used the HSM programmatic interfaces
> directly to issue certificates, thus bypassing any checks CAA would
> imply.
>> ...
>> It's another reason I like DANE and CT better.
> fortunately you don't have to pick one; use both ;)
> --
> Too many emails? Unsubscribe, change to digest, or change password by emailing moderator at companys at or changing your settings at

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <>

More information about the liberationtech mailing list