The SSL certificate authorities like Comodo that have had their security undermined by hackers shouldn't be trusted, and in fact, the way the entire SSL certificate industry of today works can and should be replaced with something better, says Moxie Marlinspike, a security expert who's come up with a plan he says will do that.
Marlinspike's plan, unveiled last August at the Black Hat Conference, is called "Convergence," and it's gaining some momentum, particularly after the shocking hacker attacks on DigiNotar, GlobalSign, Comodo, and other SSL certificate authorities of late that resulted in fake certificates coming into use on the web, including a fake Google certificate, since revoked.
Marlinspike's Convergence is radically different from the situation today where the Web of trust is based on a SSL server certificate signed by a certificate authority and recognized by the user's browser, based on recognition of the certificate authority that's programmed in by the browser vendors.
Marlinspike thinks this whole system -- which props up the multi-million-dollar certificate authority business today -- should be dumped in favor of the idea of the user more directly controlling how the browser trusts certificates based on so-called Convergence "notaries" proving online feedback about what to trust.
To work, the user needs to have Firefox browser plug-in for Convergence that Marlinspike makes available.
"Originally, I was the only notary," says Marlinspike, noting that today there are more than 50 Convergence notaries, including Electronic Frontier Foundation and security vendor Qualys. The idea is that the Convergence notaries, based on the user's own selection of which ones they prefer, electronically inform the user if the SSL certificate is considered valid. Marlinspike says there are 30,000 active Convergence users today.
Marlinspike's ideas are starting to get some support from the security industry. Qualys Director of Engineering Ivan Ristic says the research Qualys has done shows Convergence is a "viable alternative" to the general way the SSL ecosystem works today, "but in order for it to be successful, it will also need a critical mass."
"We have been researching the SSL ecosystem for some time now â€” publishing our tools and documentation on the SSL Labs web site â€” so it was only natural that we took interest in Convergence, which aims to solve some of the inherent security issues in the way we currently determine trust," Ristic says.