HOME · Twitter · Flickr · LinkedIn · publications · @ Ars Technica · Running IPv6 (Apress, 2005) · BGP (O'Reilly, 2002) · BGPexpert.com · presentations · iljitsch@muada.com

Should we simply invalidate ALL pre-heartbleed certificates?

Posted 2014-04-18

Reading Bruce Schneier's blogpost on the heartbleed bug:

❝I'm hearing that the CAs are completely clogged, trying to reissue so many new certificates. And I'm not sure we have anything close to the infrastructure necessary to revoke half a million certificates.❞

Wouldn't it make sense to simply invalidate update SSL implementations to reject all certificates that predate the discovery of the heartbleed vulnerability? Even if all the the potentially compromised certs are added to revocation lists, most clients don't check for revoked certificates, leaving a huge opportunity for man-in-the-middle attacks using the compromised certificates.

Search for:
RSS feed (no photos) - RSS feed (photos only)
Home, archives: 2007, 2008, 2009, 2010, 2011, 2012, 2013, 2014