Certified lies: detecting and defeating government interception attacks against SSL (short paper)

  • Authors:
  • Christopher Soghoian;Sid Stamm

  • Affiliations:
  • Center for Applied Cybersecurity Research, Indiana University;Center for Applied Cybersecurity Research, Indiana University

  • Venue:
  • FC'11 Proceedings of the 15th international conference on Financial Cryptography and Data Security
  • Year:
  • 2011

Quantified Score

Hi-index 0.00

Visualization

Abstract

This paper introduces the compelled certificate creation attack, in which government agencies may compel a certificate authority to issue false SSL certificates that can be used by intelligence agencies to covertly intercept and hijack individuals' secure Web-based communications.