Earlier quoted context omitted.
There is a Name Constraints extension in X.509[1] that does exactly that, but to my knowledge no browser implements it. [1] https://tools.ietf.org/html/rfc5280#section-4.2.1.10
and that would have to be baked into the CA certificate, not specified when the CA is trusted. I dont want my browser to ask the CA what it's allowed to do, i want to tell it what it's allowed to do
MITM on HTTPS traffic in Kazakhstan
461–470 of 471 posts
Re: MITM on HTTPS traffic in Kazakhstan
#462A fellow from Kazakhstan here. Banning this certificate or at least warning the users against using it WILL help a lot. Each authoritarian regime is authoritarian in its own way. Kazakhstan doesn't have a very strong regime, especially since the first president resigned earlier this year. When people protest strongly against something, the government usually backs down. For example, a couple of years ago the governme…
But there is a minor remark I have to make here. I'm sure you were talking about citizens of Kazakhstan, when you used the word "Kazakhs". The word "Kazakh" actually denotes an ethnicity, not a citizenship. And although Kazakhs are predominant ethnicity in Kazakhstan (~65% of the population), there are many others, and it's incorrect to call them Kazakhs.
Wikipedia suggests "Kazakhstani" as a English term for Kazakhstan citizens. I also saw other people using the word "Kazakhstanians". Maybe one of these two would be a better choice than "Kazakhs".
Re: MITM on HTTPS traffic in Kazakhstan
#463Hijacking the comment for better visibility. After getting some backlash, the government has already backed down. They claim that installing the certificate is entirely voluntary. https://rus.azattyq.org/a/30064788.html They have been talking about this stuff for some years, though. It will get implemented at some point. I have a feeling it was one of their "test trials": can we boil the frog yet, or do we have to he…
Re: MITM on HTTPS traffic in Kazakhstan
#464A fellow from Kazakhstan here. Banning this certificate or at least warning the users against using it WILL help a lot. Each authoritarian regime is authoritarian in its own way. Kazakhstan doesn't have a very strong regime, especially since the first president resigned earlier this year. When people protest strongly against something, the government usually backs down. For example, a couple of years ago the governme…
I totally agree with your point. Blocking this certificate in major browsers or warning users would be of great use. But there is a minor remark I have to make here. I'm sure you were talking about citizens of Kazakhstan, when you used the word "Kazakhs". The word "Kazakh" actually denotes an ethnicity, not a citizenship. And although Kazakhs are predominant ethnicity in Kazakhstan (~65% of the population), there are…
Re: MITM on HTTPS traffic in Kazakhstan
#465Earlier quoted context omitted.
Not when the cert has been previously CT and Staple preloaded I suspect?
If a user manually imports a CA, it bypasses protections like CT [1]. This is a feature specifically designed to allow MITM for corporate proxies. Always seemed like a misfeature to me, but all the browsers do it. [1] https://chromium.googlesource.com/chromium/src/+/master/net/...
Re: MITM on HTTPS traffic in Kazakhstan
#466Earlier quoted context omitted.
No, although the root itself could be scoped that way with an X.509 name constraint. But if you add the root then I believe there's no browser policy to otherwise limit the names for which it can be trusted.
Actually true root certs when evaluated by the browsers will have their name constrains within the root certificate themselves ignored. Modern browsers do respect name constraints of intermediate issuing certificates.
Re: MITM on HTTPS traffic in Kazakhstan
#467Earlier quoted context omitted.
You might be able to make intranet.company-name.tld and have a parking page on the company-name.tld and use that to get a wildcard cert that can be used for the internal pages.
Which you distribute to thousands of people on tens of thousands of devices?
Re: MITM on HTTPS traffic in Kazakhstan
#468Earlier quoted context omitted.
Then just use a wildcard cert.
Wildcard certs are a security ops nightmare. You really don't want to throw the private key for that around to every small project, and you need some good, automated way of rolling them across multiple services. Doable, but if you can avoid this, it's a better to avoid.
Re: MITM on HTTPS traffic in Kazakhstan
#469A fellow from Kazakhstan here. Banning this certificate or at least warning the users against using it WILL help a lot. Each authoritarian regime is authoritarian in its own way. Kazakhstan doesn't have a very strong regime, especially since the first president resigned earlier this year. When people protest strongly against something, the government usually backs down. For example, a couple of years ago the governme…
I totally agree with your point. Blocking this certificate in major browsers or warning users would be of great use. But there is a minor remark I have to make here. I'm sure you were talking about citizens of Kazakhstan, when you used the word "Kazakhs". The word "Kazakh" actually denotes an ethnicity, not a citizenship. And although Kazakhs are predominant ethnicity in Kazakhstan (~65% of the population), there are…
Re: MITM on HTTPS traffic in Kazakhstan
#470Earlier quoted context omitted.
I totally agree with your point. Blocking this certificate in major browsers or warning users would be of great use. But there is a minor remark I have to make here. I'm sure you were talking about citizens of Kazakhstan, when you used the word "Kazakhs". The word "Kazakh" actually denotes an ethnicity, not a citizenship. And although Kazakhs are predominant ethnicity in Kazakhstan (~65% of the population), there are…
While technically this is true, it is rare (and sounds nerdy) for English speakers who are familiar with Kazakhstan to actually use the word "Kazakhstani" or especially "Kazakhstanian." The word "Kazakh" is used informally to refer to natives or citizens of Kazakhstan when the meaning is clear from the context. Similar to how "Americans" (which could arguably refer to any North or South American) is used instead of "…
But I'm still skeptical about it. I think in my own speech I'll stick to "Kazakhstanian" (despite the word "Kazakh" is so much easier to type). Because I'm just used to make distinction between words "Kazakh" and "Kazakhstanian" when I speak Kazakh and Russian languages (most popular ones in Kazakhstan).