Iran forged the wrong SSL certificate
21–30 of 115 posts
Re: Iran forged the wrong SSL certificate
#22Just by having a forged SSL Certificate for ssl.google-analytics.com how can they supply their javscript ? The request still goes to the google servers and not to any evil-democracy-suppressors.gov.ir So sure if they could reroute the request to their servers evil things could be done. But they can NOT. Or am i missing something ?
The government almost certainly controls all internet traffic entering or leaving the country at the ISPs, and could intercept and/or redirect it as necessary.
Re: Iran forged the wrong SSL certificate
#23We don't know that they didn't get a forged certificate for ssl.google-analytics.com. Diginotar haven't (AFAIK) released even a partial list of affected domains, other than admitting that there were quite a lot of them.
Re: Iran forged the wrong SSL certificate
#24Moxie Marlinspike pointed out that it was his script 'sslsniff' that the hackers downloaded to carry out the attack. They didn't even change IPs from the one they used to download 'sslsniff' to the one used in the attack. The lesson: this could have been carried out by a script kiddie.
The head of security companies implying that hacking attacks must be caused by a state actor, simply because they don't understand the attack, creates a frightful prospect for the future of world security. Take these claims with a grain of salt. So long for 'sophisticated state actors'.
Re: Iran forged the wrong SSL certificate
#25Just by having a forged SSL Certificate for ssl.google-analytics.com how can they supply their javscript ? The request still goes to the google servers and not to any evil-democracy-suppressors.gov.ir So sure if they could reroute the request to their servers evil things could be done. But they can NOT. Or am i missing something ?
I don't think the Iranian government has any difficulty forcing telecommunications companies to install filtering / interception boxes.
Re: Iran forged the wrong SSL certificate
#26All this SSL spoofing of late coincides nicely with the adoption of "always on https" by facebook/google/twitter/et al.
Re: Iran forged the wrong SSL certificate
#27I use NoScript. google-analytics is never activated.
Re: Iran forged the wrong SSL certificate
#28A solution: http://www.convergence.io
Until this incident DigiNotar seemed trustworthy.
Re: Iran forged the wrong SSL certificate
#29Just by having a forged SSL Certificate for ssl.google-analytics.com how can they supply their javscript ? The request still goes to the google servers and not to any evil-democracy-suppressors.gov.ir So sure if they could reroute the request to their servers evil things could be done. But they can NOT. Or am i missing something ?
* Force every ISP/Telco within their borders to add fake google.com entries to their DNS servers.
and/or
* Force every ISP/Telco to transparently proxy all DNS traffic and provide fake replies for google.com queries
You can even make it easier:
Just hijack IP routing at the borders, such that IP traffic to 209.85.149.99 (and all other google networks) are not routed to the real google servers on the internet, but their own malicious filtering proxies.
Even without involving the ISPs/Telcos, they could transparently hijack and proxy you, for a whole country it might be a rather big task though, but here's what you do:
* Find all the cables carrying internet traffic in/out of your country.
* Bring a shovel, dig up the cables.
* break the cables.
* hook up the cables to your transparent proxy/filtering machinery.
Done properly, all everyone would know know was some lights flickering in the few seconds the cables were broken.
Re: Iran forged the wrong SSL certificate
#30A solution: http://www.convergence.io
And how do you choose who to trust? Until this incident DigiNotar seemed trustworthy.
This project is in its infancy, so get involved, set up a Notary, contribute on GitHub.