• Home
  • Blog
  • Projects
    • QWcrm
    • Joomla
      • mod_helloworld
      • plg_helloworld
      • QWRealURL
  • KB
    • Articles
    • Links
  • Forum
  • Stuff
    • Links
  • Search
  • Login
QuantumWarp QuantumWarp QuantumWarp
  • Home
  • Blog
  • Projects
    • QWcrm
    • Joomla
      • mod_helloworld
      • plg_helloworld
      • QWRealURL
  • KB
    • Articles
    • Links
  • Forum
  • Stuff
    • Links
  • Search
  • Home >
  • KB >
  • Links >
  • Web Server >
  • Articles >
  • SSL >
  • Extended Validation Certificates and MITM Attacks >
  • Breaking the Security Myths of Extended Validation SSL Certificates - PDF
Plusnet - Header Banner

Breaking the Security Myths of Extended Validation SSL Certificates - PDF

A PDF article covering:

Introduction

  • SSL certificate authorities have been thoroughly broken in the last year or two
  • EV-SSL is often seen as a stronger assurance of site security
  • If SSL is broken, can we trust EV-SSL?
  • No! A rogue non-EV certificate can be used to do MITM attacks against EV sites

Organization

  • State of the SSL PKI
  • EV to the rescue
  • Breaking EV certificates
    • mixed content attacks
    • same origin attacks
    • SSL rebinding
    • cache poisoning
  • Fixing this mess

Listing Details

https://www.trailofbits.com/resources/ev_ssl_mitm_slides.pdf
Website
www.trailofbits.com/resources/ev_ssl_mitm_slides.pdf
Visited
82

Legal

  • Attribution
  • DMCA
  • Privacy & Cookies
  • Terms & Conditions

Resources

  • Feedback
  • Downloads
  • Typography

QuantumWarp

  • About
  • Contact

Follow Us

  • GitHub
© QuantumWarp 2020, Powered by Astroid. Developed by QuantumWarp