[4065] in cryptography@c2.net mail archive

home help back first fref pref prev next nref lref last post

Re: lifetime of certs now in circulation

daemon@ATHENA.MIT.EDU (John R Levine)
Mon Jan 25 17:56:04 1999

Date: Mon, 25 Jan 1999 16:09:55 -0500 (EST)
From: John R Levine <johnl@iecc.com>
To: Dan Geer <geer@world.std.com>
Cc: cryptography@c2.net
In-Reply-To: <199901251953.AA09739@world.std.com>

> The ones that are in the 2020 foresight group,
> VeriSign, Microsoft, TC TrustCenter, and Thawte
> really ought to have their heads examined or I'm
> too dense to get the joke.

I suspect that the message here is that they're more worried about user
browers popping up "this certificate has expired" messages as happened to
Thawte customers with users running slightly old versions of Netscape, than
are worried about their certs being cracked. 

Besides, aren't those certs about equally strong as the ones they certify? 
If in 2018 someone can fake a cert signed by Microsoft, they can equally well
fake the signing cert. 

Regards,
John Levine, johnl@iecc.com, Primary Perpetrator of "The Internet for Dummies",
Information Superhighwayman wanna-be, http://iecc.com/johnl, Sewer Commissioner
Finger for PGP key, f'print = 3A 5B D0 3F D9 A0 6A A4  2D AC 1E 9E A6 36 A3 47 



home help back first fref pref prev next nref lref last post