SSL Was Broken by Design

October 4th, 2011

Via: Cryptome:

So how was it that Netscape SSL had exactly the same faults as IPsec, ISAKMP, Oakley, IKE? Political pressure! Somebody really REALLY wanted to be able track users and intercept/substitute….

Do I have proof? No, it’s merely circumstantial. Also, my multi-year FBI personal investigation over PPP CHAP was coincidental, too.

Netscape caved, for their commercial interests. There was also the CA business model. User’s own interests took last place.

So, arguing about ease of use is a waste of time, as long as the easy to use protocol was designed to be broken. It really is time to start over.

Leave a Reply

You must be logged in to post a comment.