<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-8271855.post7025726261764724675..comments</id><updated>2008-12-25T23:29:45.701-08:00</updated><category term='April Fool'/><category term='Tech'/><category term='CYG'/><category term='comic'/><category term='BarCamp'/><category term='interview'/><category term='geeks'/><category term='Events'/><category term='Security'/><category term='clubhack'/><category term='Fun Blogging'/><category term='Google'/><title type='text'>Comments on Thoda sa main...(A little bit of me): UNtrusted Certificates from UNtrusted CA</title><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://blog.rohit11.com/feeds/7025726261764724675/comments/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8271855/7025726261764724675/comments/default'/><link rel='alternate' type='text/html' href='http://blog.rohit11.com/2008/12/un-trusted-certificates-from-un-trusted.html'/><author><name>Rohit Srivastwa</name><uri>http://www.blogger.com/profile/10024873320275519064</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='32' src='http://1.bp.blogspot.com/-vZJ11BL13JY/TnrVuejvMTI/AAAAAAAAGTw/ZUH-w9upL38/s220/rohit.png'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>1</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-8271855.post-8510953220309949983</id><published>2008-12-25T23:29:00.000-08:00</published><updated>2008-12-25T23:29:00.000-08:00</updated><title type='text'>Rohit,&lt;br&gt;&lt;br&gt;it also is a case with the a stolen ...</title><content type='html'>Rohit,&lt;BR/&gt;&lt;BR/&gt;it also is a case with the a stolen id of the certificate.&lt;BR/&gt;&lt;BR/&gt;I has happened in the past with netgear switches. If you are to generate a  cryptographic key - netgear used to genereate only a specific number of key id's and then recycle them.&lt;BR/&gt;&lt;BR/&gt;once this was figured out we could use the same certificate - play around with the time and ids and lo - we are ready with a new phised cert&lt;BR/&gt;&lt;BR/&gt;although this bug was fixed - but it is still possible with other vendors.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8271855/7025726261764724675/comments/default/8510953220309949983'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8271855/7025726261764724675/comments/default/8510953220309949983'/><link rel='alternate' type='text/html' href='http://blog.rohit11.com/2008/12/un-trusted-certificates-from-un-trusted.html?showComment=1230276540000#c8510953220309949983' title=''/><author><name>$!ddh@rth</name><uri>http://www.blogger.com/profile/06746511077435056249</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='21' height='32' src='http://1.bp.blogspot.com/_xU2yd7PaZrA/SU2rR26mHqI/AAAAAAAAAFw/iVJr3o0j7nA/S220/VEN_0160+(Large).JPG'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.rohit11.com/2008/12/un-trusted-certificates-from-un-trusted.html' ref='tag:blogger.com,1999:blog-8271855.post-7025726261764724675' source='http://www.blogger.com/feeds/8271855/posts/default/7025726261764724675' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1729737343'/></entry></feed>
