Metadata "trust"

RL 'Bob' Morgan rlmorgan at washington.edu
Mon Mar 19 15:48:19 GMT 2012


On Mon, 19 Mar 2012, Christopher Bongaarts wrote:

> Not to mention that there's nothing precluding the metadata at, say, 
> www.providerA.com from "accidentally" including bogus data for an 
> entityID for competitorB.com (this is one of the reasons why 
> automatically loading metadata, even signed metadata, is risky).

Right, this is entirely analogous to the main problem of the public CA 
infrastructure, that in general any CA can issue a cert for any name and 
relying parties will accept it because there is no basis for filtering.

The problem of "who can can be trusted to say what" is the most profound 
in security (in life, perhaps).

  - RL "Bob" (just sayin')



More information about the users mailing list