Law Enforcement Appliance Subverts SSL
1–10 of 42 posts
Re: Law Enforcement Appliance Subverts SSL
#2Re: Law Enforcement Appliance Subverts SSL
#3The appliance itself doesn't seem that important. The big thing I take from the article is law enforcement needs to: "persuade one of the Certificate Authorities — using money, blackmail or legal process — to issue a fake certificate for the targeted website." If you can get a forged certificate from a trusted cert provider, then there is a bunch of ways to do this. The box is just a convenience.
Re: Law Enforcement Appliance Subverts SSL
#4The real news will be if anyone can prove that a default CA has been compelled by court order to generate a fake certificate.
Re: Law Enforcement Appliance Subverts SSL
#5The appliance itself doesn't seem that important. The big thing I take from the article is law enforcement needs to: "persuade one of the Certificate Authorities — using money, blackmail or legal process — to issue a fake certificate for the targeted website." If you can get a forged certificate from a trusted cert provider, then there is a bunch of ways to do this. The box is just a convenience.
Re: Law Enforcement Appliance Subverts SSL
#6I'm game if someone else is.
Re: Law Enforcement Appliance Subverts SSL
#7The appliance itself doesn't seem that important. The big thing I take from the article is law enforcement needs to: "persuade one of the Certificate Authorities — using money, blackmail or legal process — to issue a fake certificate for the targeted website." If you can get a forged certificate from a trusted cert provider, then there is a bunch of ways to do this. The box is just a convenience.
Looks like all it does is replace a SSL MITM proxy.
Re: Law Enforcement Appliance Subverts SSL
#8Earlier quoted context omitted.
Looks like all it does is replace a SSL MITM proxy.
The real bad guys can just use symmetric encryption, with keys distributed by mail or by hashing parts of certain books. It's the typical end-user going to their banking site or reading their email that's most vulnerable to such devices. China might be a top customer.
Re: Law Enforcement Appliance Subverts SSL
#9The appliance itself doesn't seem that important. The big thing I take from the article is law enforcement needs to: "persuade one of the Certificate Authorities — using money, blackmail or legal process — to issue a fake certificate for the targeted website." If you can get a forged certificate from a trusted cert provider, then there is a bunch of ways to do this. The box is just a convenience.
Re: Law Enforcement Appliance Subverts SSL
#10Shouldn't it be possible to detect when this is happening, and who's issuing the certificates? We need a plugin that snarfs the certificates as they hit your browser, and a web service to log them to (send the SHA256 of the cert, and if it's not already there, send the complete contents of the cert). I'm game if someone else is.