A Scanning Tool for PC Root Public Key Stores

Adil Alsaid, Chris J. Mitchell · 2005

Abstract: As has recently been demonstrated, a malicious third party could insert a self-issued CA public key into the list of trusted root CA public keys stored on an end user PC. As a consequence, the malicious third party could potentially do severe damage to the end user computing environment. In this paper, we discuss the problem of fake root public keys and suggest a solution that can be used to detect and remove them. We further describe a prototype implementation of this solution.

Read the paper · More papers on PaperTik