Changes to Trusted Certificate Authorities in Android Nougat
71–80 of 103 posts
Re: Changes to Trusted Certificate Authorities in Android Nougat
#72There are several ad blocking solutions for Android which involve creating a VPN connection which terminates to an app local to the device. This allows the app to filter all traffic for ads including ads inside apps. These solutions depend on installing a user CA certificate in order to filter TLS connections. I wonder how much preventing these type of ad blockers played into this decision.
Can you point me to one? Sounds neat.
I guess I was was wondering how Google would resolve the conflict between their basic function -- making money by serving ads -- with a user experience which is almost always improved by blocking ads.
Mobile chrome will never have extensions, excuses side, because Google had the opportunity with a new platform and new browser to make sure ad blocking wasn't as easy as installing an extension.
I personally run mobile Firefox with ublock origin. Wonder if that will be always be possible?
If I need to root my phone to get a system level VPN / firewall / adblocker, I might as well just get an iPhone and jailbreak.
Re: Changes to Trusted Certificate Authorities in Android Nougat
#73Taking away the user's ability to manage their own security should bring with it the responsibility - and liability - for any problems that derive from the imposed settings. The paternalistic attitude that users are and always will be ignorant is not only offensive. it is counterproductive. Security is not a product, and keeping people ignorant of the trust models they are relying on is a recipe for disaster in the l…
However, I think this is generally a good thing. When Android has 50 different OEMs (or whatever the number is), then some standardization is a good thing for the user.
You don't want Samsung or Huawei or some local Turkish OEM, or perhaps even the retailers themselves (as we've often seen with malware on imported Chinese phones) to start loading up certificates in a device before selling it. Think about what Lenovo and Dell, or all the anti-virus companies, are doing with their own certificates to PC users because Windows allows people to install their own certificates.
Also, in some countries, such as Kazakhstan, they want to start requiring users to download the "national security certificate" and install it in their devices.
This policy would prevent all of those things. That doesn't mean we still won't see CNNIC and Blue Coat/Symantec and other untrustworthy certificates loaded up by default in all Android devices (which you can still disable yourself), but I think overall this is still a good move from Google.
Re: Changes to Trusted Certificate Authorities in Android Nougat
#74Earlier quoted context omitted.
And how can I add the CA of my university, for example, which is required for some university networks? Especially because it has to be in the global store? Or how am I supposed to use my legal right to reverse and understand the functionality and APIs of software I have installed? EDIT (as I can’t create new comments for the next hour): The certificate is not used for HTTPS – but for TLS for IMAP, for example, and f…
It seems likely the email app would opt in to user certificates. Once the university (and their providers) have modified their apps to opt in, the user sees a net benefit. I guess it might be hilariously optimistic to expect the university and all of their providers to actually fix their software, but that's the other way of looking at that specific problem.
Others are using GMail, or AOSP mail, etc.
You can’t seriously expect every single Android app to add the feature back, do you?
And even then, I still get no benefit – I have to update my own fork of AOSP mail, too, I have to update a bunch of system apps, I can’t use eduroam properly anymore, and I can’t MitM the traffic of my own device anymore. The only thing this does is my life worse.
Every single Android update since KitKat has done that. Made my life worse. Removed features, killed AOSP stuff, moved code into proprietary apps, and prevent people from modifying their own device.
Re: Changes to Trusted Certificate Authorities in Android Nougat
#75Earlier quoted context omitted.
Accepting a university cert seems like a terrible idea. I would look into a mobile hotspot or, even better, transferring to a different university. https://security.stackexchange.com/questions/104576/my-colle...
Do you trust your university more, or "TÜRKTRUST Elektronik Sertifika"? Who is that, you ask? That is precisely my point. I have no idea, none at all. I do happen to know what my university was (and why it was running its own CA). Yet, this one is doubleplusgood for me. Trust Google, it knows best. (I went to my Android's builtin trusted CA list, this was the very first one - out of a list of about 100, or maybe 200)
1. The university is explicitly asking to MITM your traffic, so that's an automatic no-go on any of my devices for me. At least other CAs will be punished if caught.
2. I'm fairly certain these university certs are not subject to certificate transparency, and even if they were, since they are explicitly designed to MITM traffic, I'm not sure that it would raise any red flags if someone other than the university was issuing these certs for inappropriate domains. At least TÜRKTRUST Elektronik Sertifika issuing inappropriate certificates are much more likely to get caught doing anything fishy (with high profile sites, anyway).
3. What you're really trusting is the vendor of whatever security gateway, not the university itself. If you look at the Security.SE thread I linked, there was an actual issue with at least one of the black box vendors. I don't think the other vendors are considerably better.
So, all-in-all, I would not accept an MITM certificate on any device that I used for anything personal, full stop.
Re: Changes to Trusted Certificate Authorities in Android Nougat
#76Earlier quoted context omitted.
It seems likely the email app would opt in to user certificates. Once the university (and their providers) have modified their apps to opt in, the user sees a net benefit. I guess it might be hilariously optimistic to expect the university and all of their providers to actually fix their software, but that's the other way of looking at that specific problem.
It’s not a university email app. I’m using K9 with that. Others are using GMail, or AOSP mail, etc. You can’t seriously expect every single Android app to add the feature back, do you? And even then, I still get no benefit – I have to update my own fork of AOSP mail, too, I have to update a bunch of system apps, I can’t use eduroam properly anymore, and I can’t MitM the traffic of my own device anymore. The only thin…
Re: Changes to Trusted Certificate Authorities in Android Nougat
#77Earlier quoted context omitted.
Do you trust your university more, or "TÜRKTRUST Elektronik Sertifika"? Who is that, you ask? That is precisely my point. I have no idea, none at all. I do happen to know what my university was (and why it was running its own CA). Yet, this one is doubleplusgood for me. Trust Google, it knows best. (I went to my Android's builtin trusted CA list, this was the very first one - out of a list of about 100, or maybe 200)
I don't particularly trust either, but: 1. The university is explicitly asking to MITM your traffic, so that's an automatic no-go on any of my devices for me. At least other CAs will be punished if caught. 2. I'm fairly certain these university certs are not subject to certificate transparency, and even if they were, since they are explicitly designed to MITM traffic, I'm not sure that it would raise any red flags if…
For example, many such university certificates are not trusted as CAs for HTTPS?
Re: Changes to Trusted Certificate Authorities in Android Nougat
#78Earlier quoted context omitted.
I don't particularly trust either, but: 1. The university is explicitly asking to MITM your traffic, so that's an automatic no-go on any of my devices for me. At least other CAs will be punished if caught. 2. I'm fairly certain these university certs are not subject to certificate transparency, and even if they were, since they are explicitly designed to MITM traffic, I'm not sure that it would raise any red flags if…
You do realize a CA can be limited to be trusted only for some things, yet not for others? For example, many such university certificates are not trusted as CAs for HTTPS?
Re: Changes to Trusted Certificate Authorities in Android Nougat
#79Earlier quoted context omitted.
If your device isn't rooted, modify the APK to opt-in and don't share it with anyone. If your device is rooted, just add your cert to the system store.
> If your device is rooted, just add your cert to the system store. So, basically the same as before, but there’s no UI for it anymore? Fuck this. I might just modify the Java SSL libs on Android to even accept my cert when cert pinning is used, if I have to spend that much effort anyway.
I get that the intention is to make the device more secure but Google's execution on this is disappointing and lazy, and the result is that my devices no longer trust me the owner, which I don't consider acceptable given the lack of liability.
I'm curious what Apple's response will be.
Re: Changes to Trusted Certificate Authorities in Android Nougat
#80Earlier quoted context omitted.
I can't really say if Google is taking this approach to secure a device from heavy handed enterprise admins; but if true, it's gone too far by allowing only the app from having private conversations with the api and not allowing the user to see what's being sent over the wire. This isn't exactly new, we do after all, have certificate pinning. But now, this certificate pinning is done at the OS level by DEFAULT, un-tr…
This may be a conspiracy theory, but how probable is that this move is instead actually motivated by app developers that want to make reverse-engeneering harder? There have been cases in the past were hidden APIs were discovered that e.g. Twitter or WhatsApp were reserving for their own apps. (Not to mention privacy leaks). This will certainly become harder with the new change.