Live data from Hacker News

Iran forged the wrong SSL certificate

daemonology.net

81–90 of 115 posts

Re: Iran forged the wrong SSL certificate

#81
post #18

Can anyone explain to me how I can open up a CA and get my CA certs distributed with browsers and JVMs and what not? Is there some sort of "IANA" that approves and manages this and why would they approve all sort of shady CAs which clearly are a dangerous weak link in the whole SSL construct.

There is no approval process, no central authority. If you want your CA in OS X, you talk to Apple, if you want it in Windows, you talk to Microsoft. If you want it in Firefox, you talk to Mozilla.

There is no central authority, but each browser does have an approval process. Most require the CA to be audited annually by an organization that does WebTrust audits. Mozilla's procedures are listed at https://wiki.mozilla.org/CA:How_to_apply

I'm not sure having a central authority would be practical, but the approval process and audits need to be more thorough to find the type of security problems that DigiNotar and Comodo had.

Re: Iran forged the wrong SSL certificate

#82
There's an easy solution here: Load Google Analytics locally. There's no urgent need to load ga.js from Google's servers; there are benefits, namely speed, utilizing client cache, and getting updates, but its core functionality does not rely on where ga.js comes from.

Then, the only resource loaded form Google's servers is http://ssl.google-analytics.com/__utm.gif, and that's just loaded via a new Image(), so even if you MITM that resource request, it doesn't execute as a script or anything similar.

Re: Iran forged the wrong SSL certificate

#83
post #78

Earlier quoted context omitted.

Then that is a fundamental problem with SSL. I am very partial to the Perspectives[1] solution. I wish it would gain more wide-spread support... [1]: http://perspectives-project.org/

It is perfectly possible to use TLS without relying on Verisign. Nothing in the protocol depends on Verisign. The protocol was built in such a way that you can run your own CA, or run no CA at all and have your system manually manage self-signed certificates. Browsers won't run without the Verisign/Thawte CA system. That's not an SSL/TLS problem; that's a browser problem. Browsers exist in a complicated ecosystem inv…

Hell, for DOD systems on secure networks, you're required to remove all of the non-DOD root CAs. No DigiNotar or GoDaddy or the hundreds of others allowed.

Re: Iran forged the wrong SSL certificate

#84
post #27
post #21

I use NoScript. google-analytics is never activated.

That advice will only affect a tiny minority of tech people. Most users rely on their browser, and have no idea what javascript even is.

Looks more like a general statement than advice. Most users would tie their dick in a knot if the browser let them. Tell people to use NoScript, at the very least for the XSS countermeasures.

Re: Iran forged the wrong SSL certificate

#85
post #43
post #42

Earlier quoted context omitted.

Yet people laugh at me for being a paranoid silly tin-foil-hat nerd if I tell them that I browse with Javascript disabled by default and if a site requires it I am more likely to simply close the tab and move on before I enable it.

I think it's time to install noscript for chrome.

Chrome has some script-control features built in that I use heavily. What would I gain from a chrome extension?

Re: Iran forged the wrong SSL certificate

#86

This is something I've been talking about for a while. Back in 2009 I gave a presentation at Virus Bulletin on JavaScript security problems and highlighted some statistics on remotely loaded JavaScript: 1. 47% of the top 1,000 web sites include google-analytics.com 2. 69% include a remotely loaded web analytics solution 3. 97% load something remotely If you can attack any of these you get access to a very large numbe…

After I started using NoScript, I was amazed at how many sites load Javascript from other sites. Google-analytics is common but I have noticed more and more sites are trying to load Facebook scripts as well. Happily, my bank doesn't load Javascript from anywhere else.

Or so you think - as the parent says, it just takes a DNS entry to make somebody else's server appear to be yours.

Re: Iran forged the wrong SSL certificate

#87
post #30

Earlier quoted context omitted.

It relies on people to set up Notaries that you can specify you trust. There are many organizations I trust. The Tor Project, EFF, my university, the local hackerspace etc. If they ran notaries, I would specify that I trust them. If a SSL Authority/Notary is hacked, you remove them from the list that you trust. At the moment, trust is not agile. Browsers specify in advance which authorities are to be trusted or not.…

I don't see how this is different (even after reading the blog above), other than reducing the initial input list of CAs. Today, if a CA gets hacked, I pull them out of my trust-chain. Either way, I have to pay attention. Help me understand how it solves this, because I do think SSL is currently quite broken and would like to see a solution.

In this case DigiNotar is being removed from browsers because nobody that lives in Mountain View happens to visit sites signed by DigiNotar. And aside from being Dutch, they're also unusually small (they only made 100k in revenue from certificate sales this year).

This is not the common case. There was a very similar incident with Comodo in March, and they weren't removed. This is because Comodo certifies some non-negligible portion of the internet (between 1/4 and 1/5th of certificates), and so removing them would break a lot of things.

The same is true for VeriSign, Thawte, Comodo RAs, Geotrust, Equifax, etc...

I don't trust any of these parties, and yet I kept them in my trust DB for years, because without them the internet was unusable.

What Convergence aims to do is make trust agility even easier than it was for DigiNotar, which itself was unusually simple for the CA model. It also aims to invert the trust relationship, and put trust decisions fully in the hands of the client.

Re: Iran forged the wrong SSL certificate

#88
post #86

Earlier quoted context omitted.

After I started using NoScript, I was amazed at how many sites load Javascript from other sites. Google-analytics is common but I have noticed more and more sites are trying to load Facebook scripts as well. Happily, my bank doesn't load Javascript from anywhere else.

Or so you think - as the parent says, it just takes a DNS entry to make somebody else's server appear to be yours.

That, or they might proxy a remote JS file through a script on their servers. I've seen that done a number of times.

Re: Iran forged the wrong SSL certificate

#89

This is something I've been talking about for a while. Back in 2009 I gave a presentation at Virus Bulletin on JavaScript security problems and highlighted some statistics on remotely loaded JavaScript: 1. 47% of the top 1,000 web sites include google-analytics.com 2. 69% include a remotely loaded web analytics solution 3. 97% load something remotely If you can attack any of these you get access to a very large numbe…

After I started using NoScript, I was amazed at how many sites load Javascript from other sites. Google-analytics is common but I have noticed more and more sites are trying to load Facebook scripts as well. Happily, my bank doesn't load Javascript from anywhere else.

> After I started using NoScript, I was amazed at how many sites load Javascript from other sites.

Not only that, but I was surprised how much paranoia-induced plugins like NoScript and RequestPolicy induce paranoia themselves. And not entirely without cause, either: sites that load 5 different analytics systems are not uncommon, and I've seen 10 different ad providers on a single page.

Re: Iran forged the wrong SSL certificate

#90
post #66

This is how you delete Diginotar from Firefox btw http://support.mozilla.com/en-US/kb/deleting-diginotar-ca-ce... but I think they just pushed new minor versions with them removed anyway.

This is how to disable it in OS X:

Utilities > KeyChain Access > System Roots (left) > All Items > find "DigiNotar Root CA" > right click, get info > expand Trust > When using this certificate, never trust

Post reply on HN