Chain of Fools - An Exploration of Certificate Chain Validation Mishaps
Offered By: Black Hat via YouTube
Course Description
Overview
Explore the critical implications of poor cryptographic API design and insecure certificate chain validation implementations in this 48-minute Black Hat conference talk. Delve into how these vulnerabilities can be exploited and examine the widespread usage of APIs like Android SafetyNet in specific verticals. Learn valuable recommendations for both implementers and cryptographic API authors, including strategies for choosing misuse-resistant cryptographic APIs and handling misuse-prone cryptographic primitives. Gain insights from speakers James Barclay, Nick Mooney, and Olabode Anise as they uncover the potential pitfalls in certificate chain validation and propose solutions to enhance security in cryptographic implementations.
Syllabus
Chain of Fools: An Exploration of Certificate Chain Validation Mishaps
Taught by
Black Hat
Related Courses
Software as a ServiceUniversity of California, Berkeley via Coursera Software Testing
University of Utah via Udacity The Hardware/Software Interface
University of Washington via Coursera Software Debugging
Saarland University via Udacity Introduction to Systematic Program Design - Part 1
The University of British Columbia via Coursera