Crypto Talk at 27C3: Is the SSLiverse a safe place? Day 2, 16:00, Saal 2
SSL/TLS is the standard when it comes to securing HTTP traffic on the internet. The authenticity of a web server is usually secured using a X.509 certificate digitally signed by a trusted certification authority (CA). All major web browsers come with a list of CAs preinstalled they assume as trustworthy. Every website can be signed by any of these CAs, so no web browser would show a warning, if www.dod.gov would be signed by a Chinese certification authority or the Deutsche Telekom.
To examine the usage of X.509 certificates for SSL/TLS, the EFF installed a SSL Observatory:
The SSL …

