SHARE
Facebook X Pinterest WhatsApp

SSL Flaw by (Browser) Design?

Written By
thumbnail
Web Webster
Web Webster
Jul 23, 2009

[ Thanks to Eddy
Nigg
for this link. ]

“Some sites reported the alleged attack on EV SSL
secured sites as a means to prove that Extended Validation (EV)
digital certificates aren’t any more secure than regular SSL
certificates. That’s obviously an interesting claim since EV
certificates traditionally cost quite a lot more than those that
don’t turn the address bar of the browsers green.

“Our two “white hats” were carefully to point out that it’s
actually not an attack on EV itself, but rather a flaw in design in
the way browsers deploy SSL. Sotirov noted that “the main point of
our research is not that it is possible to capture everything
transmitted during an SSL session. It is that man-in-the-middle
attacks against EV SSL certificates are possible if the attacker
has a regular (non-EV) certificate for the same domain name.”

Complete Story

thumbnail
Web Webster

Web Webster

Web Webster has more than 20 years of writing and editorial experience in the tech sector. He’s written and edited news, demand generation, user-focused, and thought leadership content for business software solutions, consumer tech, and Linux Today, he edits and writes for a portfolio of tech industry news and analysis websites including webopedia.com, and DatabaseJournal.com.

Recommended for you...

How to Install Immich on openSUSE
r00t
Sep 6, 2024
Beginners Guide for ID Command in Linux
Benny Lanco
Sep 5, 2024
[Fixed] An Unexpected Error Occurred on Gnome Extensions
Patrick
Sep 3, 2024
Run a Google Search From the Linux Command Line With Googler
TechRepublic
Aug 27, 2024
Linux Today Logo

LinuxToday is a trusted, contributor-driven news resource supporting all types of Linux users. Our thriving international community engages with us through social media and frequent content contributions aimed at solving problems ranging from personal computing to enterprise-level IT operations. LinuxToday serves as a home for a community that struggles to find comparable information elsewhere on the web.

Property of TechnologyAdvice. © 2025 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.