Thread
Stories related to "DNS security is a decades-old issue that shows no signs of being fully resolved. Here's a quick overview of some of the problems with proposed solutions and the best way to move forward." across the full archive.
Enhancing digital certificate security (fake *.google.com SSL cert issued)
(googleonlinesecurity.blogspot.de)
A little over a year ago I posted a story called ["Configuration files are a canary, warning us of potential security issues"](https://lobste.rs/s/to8wpr/configuration_files_are_canary_warning). My basic argument was that it was fundamentally bad for security to have people growing software stacks b...
Abstract: "X.509 certificate parsing and validation is a critical task which has shown consistent lack of effectiveness, with practical attacks being reported with a steady rate during the last 10 years. In this work we analyze the X.509 standard and provide a grammar description of it amenable to t...