Digital identity security architecture in Ethos
W. Michael Petullo, Jon A. Solworth · 2011
Certificate systems often provide a foundation for distributed system security. A certificate is a signed statement; the user's private key must have been used to create the certificate's signature and the resulting certificate is tamper evident. Despite being based on sound theory, certificate system implementations are often exploited. Furthermore, certificate systems are often complex, to the extent that user-space programmers avoid certificates in favor of less secure, but easier to program, mechanisms.