[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Message-ID: <AANLkTinqTk0ccysdXpE5EMJY0U8iv4hH08Q9kH+i62nH@mail.gmail.com>
Date: Wed, 8 Sep 2010 13:53:28 -0500
From: Andrew Auernheimer <gluttony@...il.com>
To: dvs@...hmail.com
Cc: Full Disclosure <full-disclosure@...ts.grok.org.uk>
Subject: Re: [GOATSE SECURITY] Clench: Goatse's way to say
"screw you" to certificate authorities
> This is no different then installing a client cert
Yes, exactly. This is as equally secure as installing a client cert.
Except it is achieved without a client cert, using only a password, in
a manner that can be more easily scaled to lots of users.
>
>
> Trying to not sound like a dick,
> dvs.
>
>
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
Powered by blists - more mailing lists