Live data from Hacker News

Http://www.google.com/wo0dh3ad

news.ycombinator.com

21–30 of 37 posts

Re: Http://www.google.com/wo0dh3ad

#21

Earlier quoted context omitted.

You'd still need some kind of software support to trigger the exploit. At which point you may as well go with a software-only attack.

Naah, if it's simply a few added instructions I agree with you. But let's think in a wider scope (disclaimer: this is not my idea, I remember reading about it a long time ago): what if a certain cryptographic "magic code" at the beginning of a memory page would trigger the execution of arbitrary code embedded in that page? Such a thing could be triggered over the network, wireless through bluetooth/wifi, or by specia…

Stuff like this would be easy to hide in the guise of "Hardware DRM."

Re: Http://www.google.com/wo0dh3ad

#25
post #10
post #6

Earlier quoted context omitted.

I guess SSL is an improvement. Now you just have to trust 2000 companies and anyone controlling their purse strings, instead of having to trust everyone. You feel safe, which is much better than being safe...

So what you are trying to convey, there is no advantage to using SSL vs. plain connection? I wonder why then they shut down SSL in my home country during elections..

There's no advantage against a motivated, state-sized actor. Against other attackers there is still substantial advantage.

Re: Http://www.google.com/wo0dh3ad

#26
post #25
post #10

Earlier quoted context omitted.

So what you are trying to convey, there is no advantage to using SSL vs. plain connection? I wonder why then they shut down SSL in my home country during elections..

There's no advantage against a motivated, state-sized actor. Against other attackers there is still substantial advantage.

Let's say there is no advantage against (maybe) the U.S. government. I fail to see how any other state or entity would be able to manipulate certificate authority chain in general.

Re: Http://www.google.com/wo0dh3ad

#27
post #26
post #25

Earlier quoted context omitted.

There's no advantage against a motivated, state-sized actor. Against other attackers there is still substantial advantage.

Let's say there is no advantage against (maybe) the U.S. government. I fail to see how any other state or entity would be able to manipulate certificate authority chain in general.

If you are a certificate authority, you can issue certificates for any domain. There is nothing in the technology preventing you from issuing a whitehouse.gov certificate merely because you are based in Iran, for example.

Re: Http://www.google.com/wo0dh3ad

#28

Earlier quoted context omitted.

Naah, if it's simply a few added instructions I agree with you. But let's think in a wider scope (disclaimer: this is not my idea, I remember reading about it a long time ago): what if a certain cryptographic "magic code" at the beginning of a memory page would trigger the execution of arbitrary code embedded in that page? Such a thing could be triggered over the network, wireless through bluetooth/wifi, or by specia…

Stuff like this would be easy to hide in the guise of "Hardware DRM."

Yes, I guess on-processor DRM and any kind of virtualisation (will the real hypervisor please stand up?) are prime suspects for this kind of thing. But they are also the most obvious, it could be cramped into everything.

It'd be mighty interesting to tear apart / scan / reverse engineer some modern CPUs like they did with the 6502. Then again, these beasts are so complex that's similar to looking for a needle in a galaxy-sized haystack.

Re: Http://www.google.com/wo0dh3ad

#29
post #27
post #26

Earlier quoted context omitted.

Let's say there is no advantage against (maybe) the U.S. government. I fail to see how any other state or entity would be able to manipulate certificate authority chain in general.

If you are a certificate authority, you can issue certificates for any domain. There is nothing in the technology preventing you from issuing a whitehouse.gov certificate merely because you are based in Iran, for example.

Who is going to sign it?

Re: Http://www.google.com/wo0dh3ad

#30
post #29
post #27

Earlier quoted context omitted.

If you are a certificate authority, you can issue certificates for any domain. There is nothing in the technology preventing you from issuing a whitehouse.gov certificate merely because you are based in Iran, for example.

Who is going to sign it?

Who is going to sign what?

If you mean the certificates that the certificate authority issues, then the certificate authority signs them itself.

If you mean who signs the certificate authority's authority certificate, then either another certificate authority signs it, or the certificate authority signs it itself and pays the browser makers to include it as a root certificate in their browsers.

I'm not sure what you're trying to get at?

Post reply on HN