Key compromise and root cert with shared key in german lawyer communication software (beA)

2017-12-23 Thread Hanno Böck via dev-security-policy
Hi, The german bar association has a software for secure communication between lawyers called "besonderes elektronisches Anwaltspostfach" (beA). They used a local https server run on the client with a valid certificate for bealocalhost.de (the domain resolves to 127.0.0.1). This means the

Re: [FORGED] Re: CA generated keys

2017-12-23 Thread Michael Ströder via dev-security-policy
Matthew Hardeman wrote: > On Wednesday, December 13, 2017 at 5:52:16 PM UTC-6, Peter Gutmann wrote: >> In all of these cases, the device is going to be a safer place to generate >> keys than the CA, in particular because (a) the CA is another embedded >> controller somewhere so probably no better