Уровень 0 · материалов: 3
В кластер входят документы, посвященные техническим и политическим аспектам управления SSL/TLS сертификатами и механизмами их проверки, и не входят документы о блокчейне, криптовалютах или государственных финансовых системах.
Общие признаки: отзыв сертификатов, безопасность HTTPS, доверенная инфраструктура интернета, EV и DV сертификаты
Группа выше: HTTPS, TLS и инфраструктура сертификатов
Смысл: The core idea is that current certificate revocation methods (CRL and OCSP) are effectively useless against active attackers due to browser 'soft-fail' logic, creating a false sense of security. The author argues for a shift toward more robust standards like OCSP Must-Staple and shorter certificate lifetimes to ensure real security in the HTTPS ecosystem.
Existing HTTPS certificate revocation mechanisms are fundamentally broken because browsers ignore them during failures, allowing attackers to use stolen keys unnoticed.
Смысл: The main idea is that Extended Validation (EV) SSL certificates no longer provide any real security or trust advantage over standard Domain Validated (DV) certificates because browsers have removed the visual cues that once distinguished them, and the manual verification process hinders modern security automation.
EV SSL certificates are effectively dead because modern browsers have removed their visual indicators and automation makes DV certificates more secure and practical.
Смысл: The main idea is that using TLS certificate revocation as a tool for geopolitical sanctions destroys the neutrality and reliability of the global internet trust infrastructure, creating a dangerous precedent for political censorship.
Thawte's revocation of TLS certificates for sanctioned Russian banks signals the end of the internet's neutral trust system by prioritizing politics over technical verification.