Live data from Hacker News

New NSA Leak Shows MITM Attacks Against Major Internet Services

schneier.com

131–140 of 149 posts

Re: New NSA Leak Shows MITM Attacks Against Major Internet Services

#131
post #75
post #73

Earlier quoted context omitted.

Yes, absolutely, there are more hurdles. As an extension of this pinning work, Trevor has also been working on a proposal for 3rd party includes that would allow you to specify a hashsum in the include line, as well as a proposal that would fix cookie scoping in backwards compatible way.

That would pretty much cover the use of CDNs that have proper versioning schemes. Analytics, however, will remain something I'm not overly fond of. For many sites it's unnecessary. For others it's something they could nearly just as easily license and deploy to their own servers. Pulling scripts in from Google Analytics, Statcounter and others -- and especially into privacy concerned apps -- is downright irresponsibl…

even Norway's tax returns site...uses external analytic scripts.

I'm curious who build that? Can they not count the filed docs.

Re: New NSA Leak Shows MITM Attacks Against Major Internet Services

#132

Earlier quoted context omitted.

Can you expand on that? Under what definition of terrorism is the NSA a terrorist organization? It seems to me that their intent to be as clandestine as possible makes them distinctly non-terroristic.

Spreading terror.

That's not their goal, though. If anything they'd prefer that everyone in the world didn't know they existed whatsoever, which is quite the opposite to what any terrorist group would like.

You could call what they do criminal, but it's not terroristic.

Re: New NSA Leak Shows MITM Attacks Against Major Internet Services

#133
post #44

Earlier quoted context omitted.

Didn't the slides show that it was the Diginotar compromise? > We cannot have untrustworthy CAs in a system based on trust. That's simply not an option. The entire CA trust model is broken. In the trust model, any CA can issue certs for any domain; so a Chinese CA could issue Google certs, or a US CA could issue certs for the Dutch government. Self-signed certs with certificate pinning are indeed more likely to be se…

DANE[0] (in combination w/ DNSSEC[1]) is starting to sound really good right about now... except that, you know, the U.S. also runs several root nameservers. [0]: https://tools.ietf.org/html/rfc6698 [1]: https://en.wikipedia.org/wiki/Domain_Name_System_Security_Ex...

Root servers simply serve the content for the root zone, ICANN generates the contents of the root zone and signs it using an elaborate system of trust: http://dns.icann.org/ksk/

Re: New NSA Leak Shows MITM Attacks Against Major Internet Services

#134
post #35

Earlier quoted context omitted.

> Right now we need to find out which (root?) CAs are compromised by the NSA. Given that basically all CAs people actually use (even in Europe) are owned by US companies, I would estimate something close to 100% of them have cooperated with the NSA at some point. Obviously there are non-US CAs like China's CNNIC but most of them won't actually sell you a certificate.

If the NSA is doing this "legally" via secret courts etc... Then you have to assume every company subject to US law can't be trusted.

...and any CA outside the US is compromised by China, India, UK, etc.

Re: New NSA Leak Shows MITM Attacks Against Major Internet Services

#135

I'd say this is likely bullshit at least that it was done against a Brazilian company. Why take the risk of getting caught and burning your ability to do this when you can get the information from Google? 1) Chrome(and some plugins) pin's certificates and would notice a man in the middle attack(unless it was done with google's key). Sure, most corporate targets probably use IE, but if anyone uses chrome on or one of…

Technically FISA only allows surveillance of foreign nationals or powers in association with a terrorist investigation[1]. No idea how closely this is enforced.

HOWEVER, there is plenty of other legislation enabling the NSA to spy on non-US parties in different circumstances.

[1] http://en.wikipedia.org/wiki/Foreign_Intelligence_Surveillan...

Re: New NSA Leak Shows MITM Attacks Against Major Internet Services

#136

I'd say this is likely bullshit at least that it was done against a Brazilian company. Why take the risk of getting caught and burning your ability to do this when you can get the information from Google? 1) Chrome(and some plugins) pin's certificates and would notice a man in the middle attack(unless it was done with google's key). Sure, most corporate targets probably use IE, but if anyone uses chrome on or one of…

Technically FISA only allows surveillance of foreign nationals or powers in association with a terrorist investigation[1]. No idea how closely this is enforced.

HOWEVER, there is plenty of other legislation enabling the NSA to spy on non-US parties in different circumstances.

[1] http://en.wikipedia.org/wiki/Foreign_Intelligence_Surveillan...

Re: New NSA Leak Shows MITM Attacks Against Major Internet Services

#137

If this is true, and that NSA has been MITMing providers like Google, they are undermining the already shabby trust the US cloud-industry has attempted to build. I doubt Google and friends are very happy about that, since that's their one big basket where all the money comes in. NSA in their eagerness to do rampant spying on everyone have had quite some collateral. They have decided to compromise the one thing which…

For what it's worth Moxie Marlinspike gave a talk a few years back about some of the major issues with SSL as it is and had an anecdote about how bad Verisign's security is including the fact that they had a major breach in which several certs were taken.

https://www.youtube.com/watch?v=Z7Wl2FW2TcA

Re: New NSA Leak Shows MITM Attacks Against Major Internet Services

#138
post #103

Earlier quoted context omitted.

if that's the case, how did they get the private key from verisign? was it stolen? did verisign simply give them it? or was it obtained under some kind of legal process? if it was under a legal process, doesn't this raise additional questions about the judicial overview - did they realise how broad this was?

Didn't Assange say in a (secretly?) recorded video where he was talking with Schmidt and another person that while the Americans got trusted root keys from Diginotar, the Chinese hacked Verisign and grabbed their root keys? I'll see if I can find the video.

Great tip! It's not exactly what you laid out, but here's the interview you're probably thinking of (ctrl+f verisign): http://wikileaks.org/Transcript-Meeting-Assange-Schmidt

Quoting Julian Assange: I have been told actually that VeriSign... has actually given keys to the US government. Not all, but a particular key.

Very interesting.

Re: New NSA Leak Shows MITM Attacks Against Major Internet Services

#139

Earlier quoted context omitted.

They already are in my book.

Can you expand on that? Under what definition of terrorism is the NSA a terrorist organization? It seems to me that their intent to be as clandestine as possible makes them distinctly non-terroristic.

"Terrorism" is, admittedly, a very ill defined term. Academics have been arguing for decades about whether or not State actions against their own people can be labelled "terrorism" or not. Given that, I won't quote a dictionary or textbook definition, but rather say that I see them contributing as a part of a larger system that seems to meet some definitions of "terrorist", at least if you believe in the existence of "state terrorism".

It seems to me that their intent to be as clandestine as possible makes them distinctly non-terroristic.

Yeah, I'll admit that's an arguable point. I haven't even made up my own mind on the "intent" aspect.

All told, labeling them a "criminal" organization would probably be better, but I think it would be wrong to overlook the role they play in allowing the US government to use fear as a tool of control.

Re: New NSA Leak Shows MITM Attacks Against Major Internet Services

#140
post #57

If this is true, and that NSA has been MITMing providers like Google, they are undermining the already shabby trust the US cloud-industry has attempted to build. I doubt Google and friends are very happy about that, since that's their one big basket where all the money comes in. NSA in their eagerness to do rampant spying on everyone have had quite some collateral. They have decided to compromise the one thing which…

The HSTS commits /maybe/ suggest that Google thinks a Verisign intermediate was signing MITMs for Google properties. They just blacklisted "VeriSignClass3SSPIntermediateCA" See: https://chromiumcodereview.appspot.com/23523051 Note that the associated bug is private ( https://code.google.com/p/chromium/issues/detail?id=173460 ). There's a good explanation of the "bad_static_spki_hashes" parameter here: http://ritter.v…

The checkin says "Win32/Sirefef.gen!C" uses it somehow. A virus that acts as a CA?
Post reply on HN