You need to enable JavaScript to use the communication tool powered by OpenWidget

Experts have learned to detect fake SSL certificates.

IT security specialists Trevor Perrin and Moxie Marlinspike have developed a way to detect fake SSL certificates. To do this, they developed an extension to the Transport Layer Security (TLS) protocol and a special application called TACK (Trust Assertions for Certificate Keys). This protocol and application are currently being studied by the Internet Engineering Task Force (IETF), the body that develops internet protocols and architecture.

The TACK application allows a domain owner to generate a private and public key pair—called TACK keys. The private key is used to sign the server's public TLS key. The public TACK key is sent to the browser and used to verify the authenticity of the TLS key signed with TACK.

Sometimes a browser can bind a public TACK key received from a server to a domain name. If an attempt is made to spoof an SSL certificate, certificate verification will fail, and the attack will fail.

As a reminder, several cases of SSL certificate substitution were reported last year, in particular from Comodo and Diginotar certification centers.

In 2011, Google proposed an HTTP extension called "public key pinning," which would allow websites to pass reliable information about a domain name's SSL certificate and the authority that issued it to the browser via an HTTP header.

  • Helpful articles

    • Glossary

      • Latest news & promotions

          Loading…