[Full-disclosure] Firefox 2.0.x: tracking unsuspecting users using TLS client certificates
Alexander Klink
a.klink at cynops.de
Fri Sep 7 23:04:11 BST 2007
Hi Peter,
On Fri, Sep 07, 2007 at 08:10:23PM +0200, Alexander Klink wrote:
> > While I can see the same use here, it seems you are saying anyone could
> > have a look at certificates on your system, while cookies generally are
> > limited to viewing by the issuing domain. What I don't understand is if
> > there is a simple of knowing what certificate to ask for? For this to be
> No, you can't really 'ask' for a certificate - the user chooses it
> (or, in this case, the browser does so automatically).
Hmmm, I stand corrected (from Erik, who else? ;-). TLS actually allows
the server to ask for a specific type and/or CA.
Best regards,
Alex
--
Dipl.-Math. Alexander Klink | IT-Security Engineer | a.klink at cynops.de
mobile: +49 (0)178 2121703 | Cynops GmbH | http://www.cynops.de
----------------------------+----------------------+---------------------
HRB 7833, Amtsgericht | USt-Id: DE 213094986 | Geschäftsführer:
Bad Homburg v. d. Höhe | | Martin Bartosch
Full-Disclosure is hosted and sponsored by Secunia.