by Chester Wisniewski

DEFCON 2011: SSL and the future of authenticity

Moxie Marlinspike proposed a solution to the ongoing trust problems in the SSL protocol. Marlinspike’s solution, Convergence, uses a series of notaries to provide a framework for detecting man-in-the-middle attacks while eliminating the need to purchase digital certificates or rely on certificate authorities.