<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-1164539484932915717.post4931443046978947666..comments</id><updated>2009-08-08T13:05:17.681-07:00</updated><title type='text'>Comments on Short packet: CAcert.org - you got what you paid for</title><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://www.shortpacket.org/feeds/4931443046978947666/comments/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1164539484932915717/4931443046978947666/comments/default'/><link rel='alternate' type='text/html' href='http://www.shortpacket.org/2008/08/cacertorg-you-got-what-you-paid-for.html'/><author><name>Kriss Andsten</name><uri>http://www.blogger.com/profile/00827476328504196461</uri><email>kriss@shortpacket.org</email></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>10</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-1164539484932915717.post-5674119593114421209</id><published>2008-09-14T16:36:00.000-07:00</published><updated>2008-09-14T16:36:00.000-07:00</updated><title type='text'>CAcert's official position was posted the followin...</title><content type='html'>CAcert's official position was posted the following day by way of a &lt;A HREF="http://blog.cacert.org/2008/08/321.html" REL="nofollow"&gt;vulnerability note&lt;/A&gt; explaining the fix that was promptly implemented. The views of individuals are at best &lt;A HREF="http://svn.cacert.org/CAcert/Policies/CAcertCommunicationPolicy.html" REL="nofollow"&gt;community views&lt;/A&gt; and do not necessarily reflect the views of CAcert, Inc. nor the community as a whole. There are many passionate people working towards a common goal and I can assure you that there are those who care greatly about security among them (myself included).&lt;BR/&gt;&lt;BR/&gt;It is worth noting that there has recently been much discussion about &lt;A HREF="https://wiki.mozilla.org/CA:Glossary" REL="nofollow"&gt;address and domain validation&lt;/A&gt; (AV, DV) and the solution passing audit &amp;amp; presented for browser inclusion will be more secure than what we have today.&lt;BR/&gt;&lt;BR/&gt;Cheers,&lt;BR/&gt;&lt;BR/&gt;Sam&lt;BR/&gt;CISSP</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1164539484932915717/4931443046978947666/comments/default/5674119593114421209'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1164539484932915717/4931443046978947666/comments/default/5674119593114421209'/><link rel='alternate' type='text/html' href='http://www.shortpacket.org/2008/08/cacertorg-you-got-what-you-paid-for.html?showComment=1221435360000#c5674119593114421209' title=''/><author><name>Sam Johnston</name><uri>http://www.blogger.com/profile/13816529874906993705</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.shortpacket.org/2008/08/cacertorg-you-got-what-you-paid-for.html' ref='tag:blogger.com,1999:blog-1164539484932915717.post-4931443046978947666' source='http://www.blogger.com/feeds/1164539484932915717/posts/default/4931443046978947666' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-1164539484932915717.post-7127031460165586328</id><published>2008-09-05T17:56:00.000-07:00</published><updated>2008-09-05T17:56:00.000-07:00</updated><title type='text'>I agree.To the people from CACert (?) who replied ...</title><content type='html'>I agree.&lt;BR/&gt;&lt;BR/&gt;To the people from CACert (?) who replied in other comments (evaldo): sorry, you totally miss the point, which makes this even more painful than it already was.&lt;BR/&gt;&lt;BR/&gt;This is astonishing... CAs are one of the only instances that need more security than a bank... what the hell does it take for people to take that seriously?&lt;BR/&gt;&lt;BR/&gt;I just do not even want to think about this any more.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1164539484932915717/4931443046978947666/comments/default/7127031460165586328'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1164539484932915717/4931443046978947666/comments/default/7127031460165586328'/><link rel='alternate' type='text/html' href='http://www.shortpacket.org/2008/08/cacertorg-you-got-what-you-paid-for.html?showComment=1220662560000#c7127031460165586328' title=''/><author><name>bubblboy</name><uri>http://www.blogger.com/profile/15047292113926318183</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.shortpacket.org/2008/08/cacertorg-you-got-what-you-paid-for.html' ref='tag:blogger.com,1999:blog-1164539484932915717.post-4931443046978947666' source='http://www.blogger.com/feeds/1164539484932915717/posts/default/4931443046978947666' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-1164539484932915717.post-3429743613211558872</id><published>2008-08-23T13:19:59.130-07:00</published><updated>2008-08-23T13:19:59.130-07:00</updated><title type='text'>So, let's only include in browsers root certs for ...</title><content type='html'>&lt;I&gt;So, let's only include in browsers root certs for CA authorities that we know have good code quality.&lt;/I&gt;&lt;BR/&gt;&lt;BR/&gt;I believe my argument was to be extremely cautious about a CA where code that shouldn't have been in production in the first place - is in production. Hence, "we know there's a pretty nasty risk here."&lt;BR/&gt;&lt;BR/&gt;As opposed to what you're saying above which is, allow me to paraphrase, "we don't know whether or not there are any risks here."&lt;BR/&gt;&lt;BR/&gt;I know it's on CAcerts radar to improve security and I believe that they have a decent shot of doing so, should they manage to find some more manpower. That doesn't really diminish the fact that there's risk, it's unnecessary, it's unwarrated and it's here today. If they manage to fix their issues in a satisfactory manner, I'll be the first guy to blog something supportive about it.&lt;BR/&gt;&lt;BR/&gt;(That's the important part of this reply. The rest is just sugar on the top..)&lt;BR/&gt;&lt;BR/&gt;&lt;I&gt;All kinds of corporations that pass all kinds of audits produce all kinds of lousy code. The only way to know whether code is really good is to publish it.&lt;/I&gt;&lt;BR/&gt;&lt;BR/&gt;..and in this case it's published and bad to the extent that I think that users shouldn't be exposed to the risk - or at the very least should be &lt;I&gt;aware&lt;/I&gt; of it. If you disagree, hey, that's fine.  Debian does too. &lt;BR/&gt;&lt;BR/&gt;&lt;I&gt;Random security researchers don't have any financial incentive to not report problems in a codebase and so they are honest.&lt;/I&gt;&lt;BR/&gt;&lt;BR/&gt;I disagree, and that's one of the reasons I'm somewhat vocal about CAcert: You can certainly &lt;A HREF="http://www.fastcompany.com/magazine/127/nexttech-fear-of-a-black-hat.html" REL="nofollow"&gt;sell&lt;/A&gt; exploits.&lt;BR/&gt;&lt;BR/&gt;&lt;BR/&gt;&lt;I&gt;Take the same security researcher and have them employed by some auditing firm and now they have an incentive to be more lax - since the guy paying the bills is the guy who wrote the code.&lt;/I&gt;&lt;BR/&gt;&lt;BR/&gt;I'm not sure what sort of experience you have with code auditors, but that doesn't sound like the norm.  Starters, the boss of the boss of the guy who wrote the code is the one likely to sign off the auditors bill and the auditors are likely to want to prove their worth as much as possible. There's absolutely no gain to being lax, when you can earn so much more in terms of brownie points by highlighting even pretty trivial downsides with the code.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1164539484932915717/4931443046978947666/comments/default/3429743613211558872'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1164539484932915717/4931443046978947666/comments/default/3429743613211558872'/><link rel='alternate' type='text/html' href='http://www.shortpacket.org/2008/08/cacertorg-you-got-what-you-paid-for.html?showComment=1219522799130#c3429743613211558872' title=''/><author><name>Kriss Andsten</name><uri>http://www.blogger.com/profile/00827476328504196461</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='03465876358571103113'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.shortpacket.org/2008/08/cacertorg-you-got-what-you-paid-for.html' ref='tag:blogger.com,1999:blog-1164539484932915717.post-4931443046978947666' source='http://www.blogger.com/feeds/1164539484932915717/posts/default/4931443046978947666' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-1164539484932915717.post-8128013663211223520</id><published>2008-08-23T11:05:36.341-07:00</published><updated>2008-08-23T11:05:36.341-07:00</updated><title type='text'>Sure, I'd agree that overall code quality is more ...</title><content type='html'>Sure, I'd agree that overall code quality is more important than whether any one particular bug is fixed.&lt;BR/&gt;&lt;BR/&gt;So, let's only include in browsers root certs for CA authorities that we know have good code quality.&lt;BR/&gt;&lt;BR/&gt;Hmm - looks like we need to get rid of all of them.  I don't know anything about verisign's code quality, and neither do you.  Sure, they passed some 3rd-party audit, but somehow I doubt that this organization is looking at their source code so much as checking that they have a board of directors and screen employees, etc.  &lt;BR/&gt;&lt;BR/&gt;All kinds of corporations that pass all kinds of audits produce all kinds of lousy code.  The only way to know whether code is really good is to publish it.  Random security researchers don't have any financial incentive to not report problems in a codebase and so they are honest.  Take the same security researcher and have them employed by some auditing firm and now they have an incentive to be more lax - since the guy paying the bills is the guy who wrote the code.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1164539484932915717/4931443046978947666/comments/default/8128013663211223520'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1164539484932915717/4931443046978947666/comments/default/8128013663211223520'/><link rel='alternate' type='text/html' href='http://www.shortpacket.org/2008/08/cacertorg-you-got-what-you-paid-for.html?showComment=1219514736341#c8128013663211223520' title=''/><author><name>gw</name><uri>http://gw.thefreemanclan.net:8765/</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.shortpacket.org/2008/08/cacertorg-you-got-what-you-paid-for.html' ref='tag:blogger.com,1999:blog-1164539484932915717.post-4931443046978947666' source='http://www.blogger.com/feeds/1164539484932915717/posts/default/4931443046978947666' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-1164539484932915717.post-4240146548855146143</id><published>2008-08-21T05:37:08.204-07:00</published><updated>2008-08-21T05:37:08.204-07:00</updated><title type='text'>"Sure, a bug is a bad thing, and you know we are w...</title><content type='html'>&lt;I&gt;"Sure, a bug is a bad thing, and you know we are working on minimizing problems."&lt;/I&gt;&lt;BR/&gt;&lt;BR/&gt;I (still) don't think that the one bug is the actual issue of a shaky code base, but it seemed prudent to move the discussion to IRC rather than run a game of blog tennis, so such was done.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1164539484932915717/4931443046978947666/comments/default/4240146548855146143'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1164539484932915717/4931443046978947666/comments/default/4240146548855146143'/><link rel='alternate' type='text/html' href='http://www.shortpacket.org/2008/08/cacertorg-you-got-what-you-paid-for.html?showComment=1219322228204#c4240146548855146143' title=''/><author><name>Kriss Andsten</name><uri>http://www.blogger.com/profile/00827476328504196461</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='03465876358571103113'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.shortpacket.org/2008/08/cacertorg-you-got-what-you-paid-for.html' ref='tag:blogger.com,1999:blog-1164539484932915717.post-4931443046978947666' source='http://www.blogger.com/feeds/1164539484932915717/posts/default/4931443046978947666' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-1164539484932915717.post-4541454461764056312</id><published>2008-08-21T03:41:25.914-07:00</published><updated>2008-08-21T03:41:25.914-07:00</updated><title type='text'>At least, we are showing you our codebase, what ab...</title><content type='html'>At least, we are showing you our codebase, what about others?. Sure, a bug is a bad thing, and you know we are working on minimizing problems.&lt;BR/&gt;&lt;BR/&gt;Now, are you right to make CAcert the martyr of your cause? Take a look at the following url. IT IS NOT JUSTIFICATION, it is just another example of how things go bad. Now, did they remove Verisign and Thawte from root lists? There were too many problems you never learned about in the CA world&lt;BR/&gt;&lt;BR/&gt;http://www.benedelman.org/news/020305-1.html</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1164539484932915717/4931443046978947666/comments/default/4541454461764056312'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1164539484932915717/4931443046978947666/comments/default/4541454461764056312'/><link rel='alternate' type='text/html' href='http://www.shortpacket.org/2008/08/cacertorg-you-got-what-you-paid-for.html?showComment=1219315285914#c4541454461764056312' title=''/><author><name>Evaldo</name><uri>http://www.blogger.com/profile/11855291806489896016</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.shortpacket.org/2008/08/cacertorg-you-got-what-you-paid-for.html' ref='tag:blogger.com,1999:blog-1164539484932915717.post-4931443046978947666' source='http://www.blogger.com/feeds/1164539484932915717/posts/default/4931443046978947666' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-1164539484932915717.post-2562527358811761770</id><published>2008-08-21T02:27:19.803-07:00</published><updated>2008-08-21T02:27:19.803-07:00</updated><title type='text'>"A lot of people criticise CACert but none of them...</title><content type='html'>&lt;I&gt;"A lot of people criticise CACert but none of them provide solutions, implement something better, or actually put their criticisms into context. You seem to be another one of those."&lt;/I&gt;&lt;BR/&gt;&lt;BR/&gt;The solution in my book is to get the root cert the hell out of anywhere even remotely mainstream until they got a grip on their operations and codebase. As for the actual coding bits, I've been (briefly) in touch with CAcert and offered some ideas about tools and practices which might make it easier to maintain. &lt;BR/&gt;&lt;BR/&gt;Compare this to any other default package, though - "There's probably bad holes in this, it's bloody hard to audit properly, users can be affected without knowing they're even at risk." - would you keep that package in the core distribution until it was fixed? Further, would you rack down on people reporting issues about it with, saying "You don't offer solutions so you don't have a say"?&lt;BR/&gt;&lt;BR/&gt;&lt;BR/&gt;&lt;I&gt;"Yet, you raise hell over the issue as if it was the worst thing ever."&lt;/I&gt;&lt;BR/&gt;&lt;BR/&gt;I think you missed the point, though: Arbitrary certificate issuing for .jp was a &lt;I&gt;case in point&lt;/I&gt; for "the codebase is horrid, there are &lt;I&gt;bad&lt;/I&gt; holes and it's pretty damn easy to run across them". One thing you didn't see was the second hole a few days later allowing arbitrary issuance of client certificates (it was posted as 'private' in their bug tracker and never publicly commented upon by myself or CAcert), and I'm guessing you also didn't  see the GPG related bugs of similar magnitude (not found by me, but see their tracker for info.)&lt;BR/&gt;&lt;BR/&gt;&lt;BR/&gt;&lt;I&gt;"You don't even /know/ of all the problems with commercial CAs, but you are willing to trust webtrust based on documents they publish?"&lt;/I&gt;&lt;BR/&gt;&lt;BR/&gt;I believe it covers enough technicalities (even though the document isn't that technical all by itself) to raise an eyebrow if the production system is running PHP with register_globals on, yes. It wouldn't cover everything, of course, and I'm not saying that other CA's are infallible either. But again, you wouldn't say "Yeah, so what, there's a bad state of affairs in Apache, but for IIS, we can't even see the code, so let's ignore the one we have at hand.", I'm guessing?&lt;BR/&gt;&lt;BR/&gt;&lt;BR/&gt;"And in as such, being the person responsible for CACert's inclusion in Debian's ca-certificates and Debian's Mozilla products, I will continue to further CACert, because I believe in what they are doing, and because you have not convinced me of anything with your slander."&lt;BR/&gt;&lt;BR/&gt;I'm sorry to see that you put politics or ideals in front of security - it doesn't make sense to me, at all. I too like the idea of CAcert, but unless they can run it like a CA should be run - with a decent baseline of security - then the 'idea' is worth jack, since PKI is all about trust in the end. You're basically implicitly granting trust for something that &lt;I&gt;does not have the ability to support it&lt;/I&gt; at this time. And you do this for millions of users, because you 'like the idea'?&lt;BR/&gt;&lt;BR/&gt;As for slander, I think that finding/reporting two pretty nasty holes, both stemming from a non-use of &lt;I&gt;anything&lt;/I&gt; resembling best practices give me the right to claim that the code is less than stellar without being called a liar.&lt;BR/&gt;Still don't believe what I'm saying? Check out the code base yourself. Takes ~5 minutes.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1164539484932915717/4931443046978947666/comments/default/2562527358811761770'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1164539484932915717/4931443046978947666/comments/default/2562527358811761770'/><link rel='alternate' type='text/html' href='http://www.shortpacket.org/2008/08/cacertorg-you-got-what-you-paid-for.html?showComment=1219310839803#c2562527358811761770' title=''/><author><name>Kriss Andsten</name><uri>http://www.blogger.com/profile/00827476328504196461</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='03465876358571103113'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.shortpacket.org/2008/08/cacertorg-you-got-what-you-paid-for.html' ref='tag:blogger.com,1999:blog-1164539484932915717.post-4931443046978947666' source='http://www.blogger.com/feeds/1164539484932915717/posts/default/4931443046978947666' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-1164539484932915717.post-601484856848472978</id><published>2008-08-21T01:01:53.468-07:00</published><updated>2008-08-21T01:01:53.468-07:00</updated><title type='text'>A lot of people criticise CACert but none of them ...</title><content type='html'>A lot of people criticise CACert but none of them provide solutions, implement something better, or actually put their criticisms into context. You seem to be another one of those.&lt;BR/&gt;&lt;BR/&gt;Before this was fixed, you could have possibly taken over some Japanese TLDs, but nobody actually knows which ones. Yet, you raise hell over the issue as if it was the worst thing ever. You don't even /know/ of all the problems with commercial CAs, but you are willing to trust webtrust based on documents they publish?&lt;BR/&gt;&lt;BR/&gt;CACert may have some way to come, but they are the only ones on the right path, if you ask me. As such, I am happy to support them, getting a lot for no pay. And in as such, being the person responsible for CACert's inclusion in Debian's ca-certificates and Debian's Mozilla products, I will continue to further CACert, because I believe in what they are doing, and because you have not convinced me of anything with your slander.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1164539484932915717/4931443046978947666/comments/default/601484856848472978'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1164539484932915717/4931443046978947666/comments/default/601484856848472978'/><link rel='alternate' type='text/html' href='http://www.shortpacket.org/2008/08/cacertorg-you-got-what-you-paid-for.html?showComment=1219305713468#c601484856848472978' title=''/><author><name>madduck</name><uri>http://madduck.net/</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.shortpacket.org/2008/08/cacertorg-you-got-what-you-paid-for.html' ref='tag:blogger.com,1999:blog-1164539484932915717.post-4931443046978947666' source='http://www.blogger.com/feeds/1164539484932915717/posts/default/4931443046978947666' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-1164539484932915717.post-1174763957656812603</id><published>2008-08-15T04:56:51.119-07:00</published><updated>2008-08-15T04:56:51.119-07:00</updated><title type='text'>I'm not really saying that you're evil, mind. The ...</title><content type='html'>I'm not really saying that you're evil, mind. The issue isn't really the specific vulnerability either (that was a case-in-point), rather the platform as a whole. &lt;BR/&gt;&lt;BR/&gt;Normally I wouldn't mind as much - shit happens and it's up to whoever is running a system to know and assess the risks, especially if the code is open.&lt;BR/&gt;Not so much with a CA though - any vulnerability on &lt;I&gt;your&lt;/I&gt; end could mean a security issue for &lt;I&gt;any user with your root cert installed&lt;/I&gt;. They wouldn't even need to know that they &lt;I&gt;have&lt;/I&gt; your root cert installed.&lt;BR/&gt;&lt;BR/&gt;Given that outset, I think your codebase really isn't suitable for the task and disclosed why I think this to be the case and why I question the judgement of operating a CA on it, seeing it doesn't really allow for either good maintainability or a good security standard (register_globals in combination with these two is outright scary)&lt;BR/&gt;&lt;BR/&gt;It's pretty hard to make that statement without it being a bit of a slap in the face. I'm aware of and sorry for that, but I can't really see how to avoid that.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1164539484932915717/4931443046978947666/comments/default/1174763957656812603'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1164539484932915717/4931443046978947666/comments/default/1174763957656812603'/><link rel='alternate' type='text/html' href='http://www.shortpacket.org/2008/08/cacertorg-you-got-what-you-paid-for.html?showComment=1218801411119#c1174763957656812603' title=''/><author><name>Kriss Andsten</name><uri>http://www.blogger.com/profile/00827476328504196461</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='03465876358571103113'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.shortpacket.org/2008/08/cacertorg-you-got-what-you-paid-for.html' ref='tag:blogger.com,1999:blog-1164539484932915717.post-4931443046978947666' source='http://www.blogger.com/feeds/1164539484932915717/posts/default/4931443046978947666' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-1164539484932915717.post-486381359262235952</id><published>2008-08-14T06:30:20.089-07:00</published><updated>2008-08-14T06:30:20.089-07:00</updated><title type='text'>CAcert has fixed the issue shortly after reported ...</title><content type='html'>CAcert has fixed the issue shortly after reported and disclosed an advisory. Looks like we are not that evil as you say. Perhaps giving us the hint before going to public shame would be a more courteous way of handling the issue. Thanks  for the bug report :) http://blog.cacert.org/2008/08/321.html</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1164539484932915717/4931443046978947666/comments/default/486381359262235952'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1164539484932915717/4931443046978947666/comments/default/486381359262235952'/><link rel='alternate' type='text/html' href='http://www.shortpacket.org/2008/08/cacertorg-you-got-what-you-paid-for.html?showComment=1218720620089#c486381359262235952' title=''/><author><name>Evaldo</name><uri>http://www.blogger.com/profile/11855291806489896016</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.shortpacket.org/2008/08/cacertorg-you-got-what-you-paid-for.html' ref='tag:blogger.com,1999:blog-1164539484932915717.post-4931443046978947666' source='http://www.blogger.com/feeds/1164539484932915717/posts/default/4931443046978947666' type='text/html'/></entry></feed>