Live data from Hacker News

Law Enforcement Appliance Subverts SSL

wired.com

21–30 of 42 posts

Re: Law Enforcement Appliance Subverts SSL

#21
post #17
post #15

Earlier quoted context omitted.

Watch what happens when we find out which CA's did this. My money is on "they do not go out of business". Give it a few months.

Especially with Americans new found willingness to accept overreaching law enforcement measures. So long as one of the right trigger words (terrorism, children) is used, the average purchaser of certificates won't blink at the idea that law enforcement completely subverted the chain of trust that enables their customers to believe they are dealing with who it says on the certificate.

Court order?

Your argument might make sense if it was law enforcement making the request. But do you really think companies should ignore court orders?

Re: Law Enforcement Appliance Subverts SSL

#22
post #3

Earlier quoted context omitted.

Looks like all it does is replace a SSL MITM proxy.

The real bad guys can just use symmetric encryption, with keys distributed by mail or by hashing parts of certain books. It's the typical end-user going to their banking site or reading their email that's most vulnerable to such devices. China might be a top customer.

What will end up happening to the 'real bad guys' http://xkcd.com/538/

Re: Law Enforcement Appliance Subverts SSL

#23
Could it be possible that GoDaddy was under court order to say that they have not had any requests? My recollection is fuzzy, I think there was a hub-bub a while back about librarians being ordered to lie about Patriot Act requests.

Re: Law Enforcement Appliance Subverts SSL

#24
post #8

Earlier quoted context omitted.

The real bad guys can just use symmetric encryption, with keys distributed by mail or by hashing parts of certain books. It's the typical end-user going to their banking site or reading their email that's most vulnerable to such devices. China might be a top customer.

Public-key encryption (such as PGP) would work as well.

Or rather Off-the-record messaging: You do not want deniability, and not leave provable traces.

Re: Law Enforcement Appliance Subverts SSL

#25
There was an article on HN earlier talking about how certificates have never actually protected anyone from fraud (fraud cites don't try to forge certificates in the first place, or so the article said). Now it gets worse -- not only is it not protecting you, but it's luring you further into a false sense of 'security' and potential government surveillance? No thanks.

Re: Law Enforcement Appliance Subverts SSL

#26
post #23

Could it be possible that GoDaddy was under court order to say that they have not had any requests? My recollection is fuzzy, I think there was a hub-bub a while back about librarians being ordered to lie about Patriot Act requests.

"The government has not had us sign a MITM certificate yet. Watch closely for the removal of this notice."

http://www.librarian.net/technicality.html

Re: Law Enforcement Appliance Subverts SSL

#27
post #6

Shouldn't it be possible to detect when this is happening, and who's issuing the certificates? We need a plugin that snarfs the certificates as they hit your browser, and a web service to log them to (send the SHA256 of the cert, and if it's not already there, send the complete contents of the cert). I'm game if someone else is.

As long as the response from the web service is signed, this could be a good solution to what I've always seen as a small vulnerability in SSL.

... assuming the web service itself is trustworthy, of course...

Re: Law Enforcement Appliance Subverts SSL

#28
post #21
post #17

Earlier quoted context omitted.

Especially with Americans new found willingness to accept overreaching law enforcement measures. So long as one of the right trigger words (terrorism, children) is used, the average purchaser of certificates won't blink at the idea that law enforcement completely subverted the chain of trust that enables their customers to believe they are dealing with who it says on the certificate.

Court order? Your argument might make sense if it was law enforcement making the request. But do you really think companies should ignore court orders?

Can a court order you to commit a fraud?

Re: Law Enforcement Appliance Subverts SSL

#29
post #6

Shouldn't it be possible to detect when this is happening, and who's issuing the certificates? We need a plugin that snarfs the certificates as they hit your browser, and a web service to log them to (send the SHA256 of the cert, and if it's not already there, send the complete contents of the cert). I'm game if someone else is.

http://www.cs.cmu.edu/~perspectives/firefox.html

A nice idea. But isn't the path from you->notaries still vulnerable to man-in-the-middle attacks? You would have to use CA authentication to verify the "notaries" you are talking to aren't fake.

Re: Law Enforcement Appliance Subverts SSL

#30
Christine Jones, the general counsel for GoDaddy — one of the net’s largest issuers of SSL certificates — says her company has never gotten such a request from a government in her eight years at the company.

Wouldn't she be required by U.S. law to say this if that's what the government told her to say?

[Edit: Seems I'm out of date; the gag-order provisions I was thinking about were ruled unconstitutional a couple of years ago: http://www.aclu.org/national-security/court-rules-patriot-ac...]

P.S. God, I hate this copy/paste Read More crap.

Post reply on HN