Live data from Hacker News

Changes to Trusted Certificate Authorities in Android Nougat

android-developers.blogspot.com

61–70 of 103 posts

Re: Changes to Trusted Certificate Authorities in Android Nougat

#61

Earlier quoted context omitted.

I believe Android is taking this approach because of hawkish network appliances vendors selling all too powerful gear to enterprises and these enterprises don't care about what to decrypt and what not and causing too many weaknesses on the way. I belive MITM decryption for enterprises is a flawed way of identifying intrusions and doesn't stop or hinder any intrusions. It only provides a false sense of security. Intru…

I can't really say if Google is taking this approach to secure a device from heavy handed enterprise admins; but if true, it's gone too far by allowing only the app from having private conversations with the api and not allowing the user to see what's being sent over the wire. This isn't exactly new, we do after all, have certificate pinning. But now, this certificate pinning is done at the OS level by DEFAULT, un-tr…

This may be a conspiracy theory, but how probable is that this move is instead actually motivated by app developers that want to make reverse-engeneering harder? There have been cases in the past were hidden APIs were discovered that e.g. Twitter or WhatsApp were reserving for their own apps. (Not to mention privacy leaks). This will certainly become harder with the new change.

Re: Changes to Trusted Certificate Authorities in Android Nougat

#62
post #55
post #52

Earlier quoted context omitted.

I joked to a friend that if Google invented a time machine, the first thing they would do is travel back to remove the extension support in Chrome before it was launched - the ad blockers.

Chrome didn't support the proper method for ad blockers at launch (it could hide content but not stop the requests, if I remember it well), and they purposely added those in months after launch, clearly for the benefit of adblocking extensions writers who where complaining. So, I don't think so.

Yes until the managements find out the they are losing Billions due to the ad blocking. IMO, not bring extension support on Chrome Android is the same reason.

Re: Changes to Trusted Certificate Authorities in Android Nougat

#64
post #61

Earlier quoted context omitted.

I can't really say if Google is taking this approach to secure a device from heavy handed enterprise admins; but if true, it's gone too far by allowing only the app from having private conversations with the api and not allowing the user to see what's being sent over the wire. This isn't exactly new, we do after all, have certificate pinning. But now, this certificate pinning is done at the OS level by DEFAULT, un-tr…

This may be a conspiracy theory, but how probable is that this move is instead actually motivated by app developers that want to make reverse-engeneering harder? There have been cases in the past were hidden APIs were discovered that e.g. Twitter or WhatsApp were reserving for their own apps. (Not to mention privacy leaks). This will certainly become harder with the new change.

Honestly, it shouldn't change that too much, since third parties like Cyanogenmod should be able to reverse the change. Of course, it's still a horrible move.

Re: Changes to Trusted Certificate Authorities in Android Nougat

#65
post #32
post #12

I feel this is a great win in terms of security for the average consumer. Sure VPN connections within organizations may get affected but the've got a workaround for that and I'm sure IT at orgs where they have an internal CA can figure it out.

The recommended path for large orgs (one of which I was recently employed at, and attached to a relevant project), is to: 1. Ensure all internal domains can also be registered externally (although the actual external registration step is optional), but this means no more .local or .companyname type TLDs internally. 2. Use an external CA to provide your certs, for both internal and external use. Obviously, this means…

Are you familiar with any CAs that will issue certs for a few hundred servers (under the same domain) that aren't on the public internet, with an automation API and at a reasonable price?

Lets Encrypt isn't an option, because (a) the servers aren't on the public internet and (b) even if they were, LE is limited to 20 certificates per domain per week.

I'm aware that Plex has some sort of deal like that, but is that a one-off thing, and if it's something any company can get in on, how expensive is it?

I know some CAs offer 'enterprise services' but their websites don't seem to spell out what that means or what it costs - just that you should contact them to schedule a demo, which probably means the costs are eye-watering.

Re: Changes to Trusted Certificate Authorities in Android Nougat

#66
post #12

I feel this is a great win in terms of security for the average consumer. Sure VPN connections within organizations may get affected but the've got a workaround for that and I'm sure IT at orgs where they have an internal CA can figure it out.

The only goal is to stop ad blocking with its own local CA installed, which impacts Google's revenue.

Re: Changes to Trusted Certificate Authorities in Android Nougat

#67
post #40

Taking away the user's ability to manage their own security should bring with it the responsibility - and liability - for any problems that derive from the imposed settings. The paternalistic attitude that users are and always will be ignorant is not only offensive. it is counterproductive. Security is not a product, and keeping people ignorant of the trust models they are relying on is a recipe for disaster in the l…

Most people don't want to be taught something like this though, and why should they? The system can do what practically everyone wants it to do without that user education overhead, which is what they are doing.

Re: Changes to Trusted Certificate Authorities in Android Nougat

#68
post #17

Earlier quoted context omitted.

I believe Android is taking this approach because of hawkish network appliances vendors selling all too powerful gear to enterprises and these enterprises don't care about what to decrypt and what not and causing too many weaknesses on the way. I belive MITM decryption for enterprises is a flawed way of identifying intrusions and doesn't stop or hinder any intrusions. It only provides a false sense of security. Intru…

In my experience enterprise MITM decrypt is not usually deployed to identify or stop intrusions. It is deployed to enforce compliance with corporate usage rules and as part of a data loss prevention solution. Quite often these are both necessary to meet regulatory requirements.

MITMing the world won't do anything against data loss.

It might "protect" you against data exposure (though I wouldn't count on it), but that shouldn't be affected by any regulators unless your employees have access to WAY too much user data.

Re: Changes to Trusted Certificate Authorities in Android Nougat

#69
post #20

This is just terrible news. Android's treatment of user-added certificates is already terribly broken (why does it warn me that my network connexions may be monitored when I install my own certificate, when Android already trusts e.g. Symantec?), and this makes it worse. What they should have done was gone the other direction entirely. If I — the owner of the phone — choose to trust a certificate authority, then ever…

For in case YOU didn't put the CA on your phone.

Re: Changes to Trusted Certificate Authorities in Android Nougat

#70
post #39
post #31

Earlier quoted context omitted.

And how can I add the CA of my university, for example, which is required for some university networks? Especially because it has to be in the global store? Or how am I supposed to use my legal right to reverse and understand the functionality and APIs of software I have installed? EDIT (as I can’t create new comments for the next hour): The certificate is not used for HTTPS – but for TLS for IMAP, for example, and f…

Accepting a university cert seems like a terrible idea. I would look into a mobile hotspot or, even better, transferring to a different university. https://security.stackexchange.com/questions/104576/my-colle...

Do you trust your university more, or "TÜRKTRUST Elektronik Sertifika"?

Who is that, you ask? That is precisely my point. I have no idea, none at all. I do happen to know what my university was (and why it was running its own CA). Yet, this one is doubleplusgood for me. Trust Google, it knows best.

(I went to my Android's builtin trusted CA list, this was the very first one - out of a list of about 100, or maybe 200)

Post reply on HN