The Sovereign Keys Project

EFF's Sovereign Keys project aims to make the encrypted Internet more reliable and secure. It is a proposal to fix structural insecurities in the way that the Web, Email and other Internet protocols currently establish encrypted connections.

If deployed, Sovereign Keys will protect HTTPS and other uses of TLS/SSL against a wide variety of attacks, including attacks involving Certificate Authorities and domain validation, and attacks that involve downgrading or blocking encrypted connections. It operates by providing an optional and very secure way of associating domain names with public keys, augmenting other methods of publishing TLS/SSL keys, such as the existing system of Certificate Authorities or proposals to publish keys via DNSSEC.

You can read a high level overview or look at the detailed design document and list of issues that we're tracking in relation to the design. There is also a public mailing list for discussion of the design.

Related Issues

Stay in Touch

NSA Spying

EFF is leading the fight against the NSA's illegal mass surveillance program. Learn more about what the program is, how it works, and what you can do.

Follow EFF

Pls plan to call your House Rep Monday, "vote no FCC privacy repeal" If your rep is Republican, ask 5 friends too https://eff.org/gopp

Mar 24 @ 4:18pm

A loophole in Australia's copyright safe harbor rules will stay open, endangering local user-generated content sites https://www.eff.org/deeplinks...

Mar 24 @ 1:37pm

In all, @agcrocker addressed the appeals court on NSLs for more than 25 minutes. Here's the full recording. https://youtu.be/ccS06CFkZ5M

Mar 24 @ 1:09pm
JavaScript license information