Metadata "trust"
RL 'Bob' Morgan
rlmorgan at washington.edu
Mon Mar 19 15:48:19 GMT 2012
On Mon, 19 Mar 2012, Christopher Bongaarts wrote:
> Not to mention that there's nothing precluding the metadata at, say,
> www.providerA.com from "accidentally" including bogus data for an
> entityID for competitorB.com (this is one of the reasons why
> automatically loading metadata, even signed metadata, is risky).
Right, this is entirely analogous to the main problem of the public CA
infrastructure, that in general any CA can issue a cert for any name and
relying parties will accept it because there is no basis for filtering.
The problem of "who can can be trusted to say what" is the most profound
in security (in life, perhaps).
- RL "Bob" (just sayin')
More information about the users
mailing list