New account and x.509 thoughts,--

Chat about just about anything else
Post Reply
mike acker
Level 6
Level 6
Posts: 1419
Joined: Wed Jul 31, 2013 6:29 pm
Location: Kalamazoo, MI

New account and x.509 thoughts,--

Post by mike acker » Sat Dec 30, 2017 8:20 am

as my daughter finished up her new account at the CU office she was invited to download the CU app to her smart phone.

I suggested to the agent at that point: this is where you should provide her with the fingerprint on your x.509 cert

why?

x.509 certs are published by assorted "CA" authorities. bogus certs can -- and have been obtained by crooks. what should be done as the account records are filed: my daughter needs the fingerprint on the CU certificate and then she needs to countersign that certificate using her copy of PGP/GPG

this will make the CU certificate VALID.

critical applications should not use certificates that have not been validated. as noted above having an assortment of so called authorities publishing certificates at fifty cents a thousand -- doesn't get the job done and certificates obtained by that means ought not to be marked as valid. they need to be verified first; then they can be validated. while many users will not understand this: the CU agent ought to.

the other issue of course -- is keeping un-authorized programming out of her phone. AAPL has been making a pretty good effort on that although some "approved" apps that have use excessive permissions -- most likely are a serious threat vector.
¡Viva la Resistencia!

deepakdeshp
Level 11
Level 11
Posts: 3856
Joined: Sun Aug 09, 2015 10:00 am

Re: New account and x.509 thoughts,--

Post by deepakdeshp » Sat Dec 30, 2017 1:35 pm

Hello,
Your signature states IBM 360 which is obsolete. What is the meaning of it?IBM mainframe running Mint?
If I have helped you solve a problem, please add [SOLVED] to your first post title, it helps other users looking for help, and keeps the forum clean.
I am using Mint 19 Cinnamon 64 bit with AMD A8/7410 processor . Memory 8GB

mike acker
Level 6
Level 6
Posts: 1419
Joined: Wed Jul 31, 2013 6:29 pm
Location: Kalamazoo, MI

Re: New account and x.509 thoughts,--

Post by mike acker » Sun Dec 31, 2017 7:04 am

deepakdeshp wrote:Hello,
Your signature states IBM 360 which is obsolete. What is the meaning of it?IBM mainframe running Mint?
it states "My Computer: IBM 360/50 circa 1975"..... the machine ran MFT/HASP in 348K memory. it has long since been sold, probably junked. the building was sold, and demolished and is now a parking lot.
¡Viva la Resistencia!

Post Reply

Return to “Open chat”