* Posts by pdw

1 publicly visible post • joined 17 Dec 2011

Security mandates aim to shore up shattered SSL system

pdw
WTF?

Shurely some mistake

> Under the current SSL system, CAs get to log each visit an IP address makes to an HTTPS page protected by one of their certificates.

What?!

The client knows the root cert (installed in O/S, browser, whatever) and the server has a series of signed certs linking back to it. There is no connection to the CA.