Re: [OT] Trusting X.509 certificate

2013-04-20 Thread MFPA
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Hi On Thursday 18 April 2013 at 11:18:39 PM, in , Jay Sulzberger wrote: > 1. Is the stack used for credit card use over the Net > sufficiently "secure"? Indeed this question is ill > defined: "secure" for what, against what? People have used pay

Re: [OT] Trusting X.509 certificate

2013-04-16 Thread MFPA
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Hi On Tuesday 16 April 2013 at 10:50:36 AM, in , Peter Lebbing wrote: > Everything the certificate "says" is under attacker > control when they redirect the HTTPS session to their > own system[1]. Which is why I also suggested searching other so

Re: [OT] Trusting X.509 certificate

2013-04-16 Thread Peter Lebbing
> You could look at the certificate your browser doesn't trust and follow up > the information it contains. You could also search the internet (and other > sources) for information about Intevation GmbH, and see if it matches what > the certificate says. Everything the certificate "says" is under