Linked by Thom Holwerda on Mon 5th Sep 2011 22:26 UTC
Permalink for comment 488633
To read all comments associated with this story, please click here.
To read all comments associated with this story, please click here.
News
Linked by Thom Holwerda on 05/18/13 21:06 UTC
Linked by Thom Holwerda on 05/18/13 7:37 UTC
Linked by fran on 05/18/13 1:38 UTC
Linked by Thom Holwerda on 05/17/13 23:35 UTC, submitted by kragil
Linked by MOS6510 on 05/17/13 22:22 UTC
Linked by Thom Holwerda on 05/17/13 22:15 UTC, submitted by Tom
Linked by Thom Holwerda on 05/16/13 21:41 UTC
Linked by Thom Holwerda on 05/16/13 17:04 UTC
Linked by Thom Holwerda on 05/16/13 13:17 UTC
Linked by Thom Holwerda on 05/16/13 12:06 UTC
More News »
Sponsored Links



Member since:
2007-09-22
If the Dutch government would get only a few things right, they would be doing things better than DigiNotar and would prevent many other attacks.
I think the Dutch government could have one team in one organisation that handle offline signing.
That means it is not in any way connected to the online world like DigiNotar.
They check a number of things (simplified):
- they receive a request by PGP-signed email
- check if they are on the contact-list and PGP checks out.
- look at the name of the request and see if it oesn't have *.google.com or other silly things like municipality X does not need to create a certificate for the website of municipality Y.
- call the people at the other end if they send the email
- check the numbers on the certificate request over the phone.
- create the certificate
- email it back, PGP signed.
Done, much more secure than what they had before.
Edited 2011-09-06 11:15 UTC