BlackHat USA 2011: SSL And The Future Of Authenticity
Sign in to YouTube
Sign in to YouTube
Sign in to YouTube
Uploaded on Aug 18, 2011
Speaker: MOXIE MARLINSPIKE
In the early 90's, at the dawn of the World Wide Web, some engineers at Netscape developed a protocol for making secure HTTP requests, and what they came up with was called SSL. Given the relatively scarce body of knowledge concerning secure protocols at the time, as well the intense pressure that everyone at Netscape was working under, their efforts can only be seen as incredibly heroic. But while it's amazing that SSL has endured for as long as it has, some parts of it -- particularly those concerning Certificate Authorities -- have always caused some friction, and have more recently started to cause real problems.
This talk will provide an in-depth examination of the current problems with authenticity in SSL, discuss some of the recent high-profile SSL infrastructure attacks in detail, and cover some potential strategies for the future. It will conclude with a software release that aims to definitively fix the disintegrating trust relationships at the core of this fundamental protocol.
For more information or download the video visit: http://bit.ly/BlackHat_USA_2011_infor...
-
Category
-
License
Standard YouTube License
Loading...
Loading...
Loading...
Loading...
Loading...
-
58:07
BlackHat USA 2011: How a Hacker Has Helped Influence the Government - and Vice Versaby Christiaan008
7,276 views
-
52:33
Defcon 18 - Practical Cellphone Spying - Chris Paget - Part.movby Hacking Conferences, Information Security, how to's
54,132 views
-
43:06
Defcon 2010 - Your ISP and the Government Best Friends Forever - Christopher Soghoian.movby Hacking Conferences, Information Security, how to's
37,891 views
-
1:32:41
Blackhat 2012 EUROPE - Workshop: Understanding Botnets By Building Oneby SecurityTubeCons's channel
20,821 views
-
47:50
DEFCON 17: More Tricks For Defeating SSLby Christiaan008
17,715 views
-
3
videos
Play all
BlackHat USA 2011by ChRiStIaAn008
-
1:15:44
BlackHat EU 2011: Keynote-Schneierby Vincenzo Tilotta
12,036 views
-
49:00
DEFCON 17: Cracking 400,000 Passwords, or How to Explain to Your Roommate why Power Bill is a Highby Christiaan008
36,494 views
-
48:54
DeepSec 2010: The Future of Social Engineeringby Christiaan008
7,459 views
-
52:50
Blackhat 2012 EUROPE - All Your Calls Are Still Belong to Us: How We Compromised the Cisco VoIP Crby SecurityTubeCons's channel
1,354 views
-
46:33
DEFCON 17: Fragging Game Serversby Christiaan008
11,244 views
-
59:45
Blackhat 2012 EUROPE - SSL/TLS Interception Proxies and Transitive Trustby SecurityTubeCons
1,107 views
-
14:00
Blackhat 2010 New threats to privacy Moxie Marlinspike Part 00by killab66661
1,186 views
-
45:29
Blackhat 2010 New threats to privacy Moxie Marlinspike Partby killab66661
867 views
-
43:54
How to Hack a Web Site - Dr. Susan Loveland - Lunchtime Talks in Science and Mathematicsby Adams State
591,343 views
-
43:10
Black Hat Spam SEOby Google Tech Talks
12,387 views
-
1:05:01
BlackHat USA 2011: Faces Of Facebook-Or, How The Largest Real ID Database In The World Came To Beby Christiaan008
12,053 views
-
14:58
DEFCON 18: How I Met Your Girlfriend 1/3by Christiaan008
192,527 views
-
46:20
DEFCON 19: SSL And The Future Of Authenticityby Christiaan008
2,275 views
-
31:37
DEFCON 17: BitTorrent Hacksby Christiaan008
8,137 views
-
47:33
DEFCON 16: Free Anonymous Internet Using Modified Cable Modemsby Christiaan008
14,042 views
- Loading more suggestions...
Top Comments
jeroeniskoning 1 year ago
Please people, listen to this genius !
Sign in to YouTube
Sign in to YouTube
DanielMarschall 1 year ago
He didn't explain how the connections to the notaries are secured... this would have been very interesting and this is probably the weak point of Convergence. Are the notaries secured by a CA signature? How do I know which notaries I should trust? And how do I get their public keys in a secure way? Is the list of default notaries really secure?
Sign in to YouTube
Sign in to YouTube
All Comments (69)
jessebickeldotcom 5 days ago
The notary certificate is included in the "bundle" that a user chooses. The bundle is the means of communicating trust of a notary to the user agent. Take a look at server/convergence-bundle.py in moxie0's github account.
Sign in to YouTube
Sign in to YouTube
Cocodrilo92 3 months ago
Most likely
Sign in to YouTube
Sign in to YouTube
Hans-Henrik Stærfeldt 4 months ago
Risking repeating a good point to sound clever. But this is a good point!
Are traffic to the notaries subject to man-in-the-middle attacks?
Sign in to YouTube
Sign in to YouTube
greg ferreira 4 months ago
thought i was smart til i listened to this, holy shit!!!
Sign in to YouTube
Sign in to YouTube
DarkVideo007 4 months ago
I love his intro!! xD
so funny
Sign in to YouTube
Sign in to YouTube
Frederik Pedersen 7 months ago
Why this not for chrome ?
Sign in to YouTube
Sign in to YouTube
someman7 7 months ago
I wouldn't know, you could perhaps check the author's website or e-mail him.
Sign in to YouTube
Sign in to YouTube
Andrei Petcu 7 months ago
No h t t p s on convergence!
Is the project dead? No more commits in the last 8 months. The project is still in beta?
Sign in to YouTube
Sign in to YouTube
someman7 8 months ago
.io? Are you kidding me? Dude.
Sign in to YouTube
Sign in to YouTube