Earlier quoted context omitted.
What browsers actually do that? And do all CAs support it? Besides, if you have enough access to the CA, you can just get whatever cert is in the transparency log, though that's almost certainly harder for most nations and CAs.
> you can just get whatever cert is in the transparency log That would require compromising the certificate requester .
0-days exploited by commercial surveillance vendor in Egypt
191–200 of 254 posts
Re: 0-days exploited by commercial surveillance vendor in Egypt
#192Earlier quoted context omitted.
> you can just get whatever cert is in the transparency log That would require compromising the certificate requester .
A lot of certificate management services for enterprise customers "helpfully" store the private key files. How many cloud or SaaS vendors automatically handle the private keys as well instead of them being generated and staying securely only on the systems using them? So there are still points of centralization to attack, potentially.
But it requires a lot more steps.
Re: 0-days exploited by commercial surveillance vendor in Egypt
#193Though HTTPS is better than nothing, and this attack relies on HTTP to inject the initial payload, state sponsored attackers in some countries can likely just subvert CA or CDN infrastructure instead.
Re: 0-days exploited by commercial surveillance vendor in Egypt
#194Earlier quoted context omitted.
Only if you pay $$$$ for OV/EV. If you get the normal DV cert they don't provide any more verification than Letsencrypt. And since browsers have moved away from indicating OV/EV certs to end users, not many organizations are paying for those anymore.
Can confirm as someone who has to renew a non-Let’s Encrypt cert every year (for reasons). The CA sends an automated email to the email address listed in WHOIS, you click a link in the email, and they issue the certificate. No human interaction necessary.
Re: 0-days exploited by commercial surveillance vendor in Egypt
#195Earlier quoted context omitted.
The archetypical EAL5 product is a smartcard or cryptographic coprocessor (same thing, different package). They're certifiable because they don't do much. But if you'd like an example from the EAL4 list: start with FortiOS.
EAL4 and under is junk (with respect to security). I already said that. The standards committee has also always maintained that there is no meaningful security at EAL4. Earlier drafts of the standards said EAL4 is only meant to protect against “casual and inadvertent attacks”. The general crappiness of EAL4 goes all the way back to the Orange Book where EAL4 maps approximately to Level C2 (contemporaneous projects go…
But upthread, you knocked Apple for not achieving an adequate assurance level. As you can see now, and from your own last comment, that doesn't make any sense. It's possible (though deeply silly) that there's some iPhone configuration that could "achieve" EAL4, but you yourself don't believe that has any meaning. I don't either.
I don't think EAL5 or EAL6 do, either, except that if you tell me your product is EAL5, I'll assume it's a small fixed-function device.
Re: 0-days exploited by commercial surveillance vendor in Egypt
#196Earlier quoted context omitted.
Or get someone to click on a spoofed domain, certified by our beloved LetsEncrypt! Apparently al that is needed is an HTTP 302/307 redirect response (or html redirect payload, maybe even DNS?) pointing the client toward c.betly[.]me
Coincidentally, the ACME DNS verification process that LetsEncrypt uses is vulnerable to the QUANTUM attack. If NSA injects a fake DNS response in the right spot, and have the their response arrive before the official response, they can get the domain verified. OTOH, Certificate Transparency Logs will give the game away, so there's that.
Re: 0-days exploited by commercial surveillance vendor in Egypt
#197If I were a government security regulator or intelligence agency, I would monitor bank accounts associated with Zerodium and similar 0day and payload marketplaces and offensive sec tools to issue a secret, internal threat forecast that marks the beginning potential of increasing, directed, high-value attacks. Probably already exists in various forms, but taking it semi-public to sensitive industries might be useful.
Re: 0-days exploited by commercial surveillance vendor in Egypt
#198Earlier quoted context omitted.
> Why do Google and Apple not simply poach these staff They do. Plenty of white hat teams hire 8200 vets, but sometimes they'd rather make their own company instead of being a cog within an amaphorous foreign corporation.
This. IIRC some famous security researcher responsible for iOS jail-breaks was poached by Apple only to leave after 3 months. Successful and skilled security people with a proven track record, don't have the paciente of putting up with the charade such large orgs require.
Re: 0-days exploited by commercial surveillance vendor in Egypt
#199Earlier quoted context omitted.
EAL4 and under is junk (with respect to security). I already said that. The standards committee has also always maintained that there is no meaningful security at EAL4. Earlier drafts of the standards said EAL4 is only meant to protect against “casual and inadvertent attacks”. The general crappiness of EAL4 goes all the way back to the Orange Book where EAL4 maps approximately to Level C2 (contemporaneous projects go…
If you're saying "EAL4 and below is junk" (I'd say EAL* is junk, but whatever), all you're really saying is that minimal-function cryptographic coprocessors are safer than operating systems and applications. Well, yeah, sure. I don't think you needed the farce of Common Criteria to tell you that, though. But upthread, you knocked Apple for not achieving an adequate assurance level. As you can see now, and from your o…
You keep calling it a farce, but you keep pointing at EAL4 and lower systems. Yes, those levels are farces, that was the whole point. Those are the levels for the certification of toys where documentation and paperwork is all that is needed, not proper design.
Complaining about the Common Criteria in the context of EAL4 and lower systems is like complaining about tissue paper manufacturers putting their tissue paper through bulletproof vest testing and certifying that it does not stop bullets. Yes, that is pretty stupid, farcical, and probably a waste of time. But no, the test is not stupid. It can test actual bulletproof vests, you just keep seeing stupid waste of time tests proving a useless fact that everybody already knows, the EAL4 quality system sucks and has no place in a serious security organization.
Re: 0-days exploited by commercial surveillance vendor in Egypt
#200Here is what I do not understand: Spyware firms and 0-day vendors both have staff dedicating to finding 0-days. Why do Google and Apple not simply poach these staff? I am sure Google and Apple can offer very competitive salaries, so why do they not do so? Is it because the cost of basically poaching all of the skilled 0-day hunters is deemed to be greater than the cost of just issuing patches?
Though poaching all is simply impossible, by raising prices you'll incentivize more people to become vulnerability researches, so more will always be available to the spyware firms