Friday, October 22, 2010

Official says government is helpless against fake security certifications

http://www.nextgov.com/nextgov/ng_20101022_1367.php

So the the government wants to control cyber security, Obama wants the kill switch, but they can't even keep their own website secure.
Yeah that makes alot of sense to me, just not common.


A White House official on Friday said fake secure websites created to steal money or personal information are a danger the government is powerless to control.

The comment from Andrew McLaughlin, White House deputy chief technology officer for Internet policy, came during a panel discussion on emerging threats to e-commerce and other online transactions hosted by Washington think tank the New America Foundation. Increasingly, all parties involved in online dealings rely on information from companies and countries with Internet policies that are beyond the federal government's jurisdiction. The participants include Internet users; websites, such as IRS.gov; browser providers, such as Google's Chrome; and certifying agents, such as VeriSign, which confirm that websites and people exchanging information are who they claim to be. These so-called certificate authorities sometimes erroneously or intentionally approve malicious websites