...not really anyway.
The user ISP would not be able to detect
certificate modification. That said, if you
define ISP as the provider of the SSL service
"you" use, then yes, that is something that the
provider needs to ensure that appropriate SSL
certificate providers are trustworthy.
The paper details the lack of oversight of
certificate issuers. The paper is well done.
Thanks for writing.
Doug
The best of ZDNet, delivered
ZDNet Newsletters
Get the best of ZDNet delivered straight to your inbox



