Live data from Hacker News

New NSA Leak Shows MITM Attacks Against Major Internet Services

schneier.com

141–149 of 149 posts

Re: New NSA Leak Shows MITM Attacks Against Major Internet Services

#141

Earlier quoted context omitted.

Your tack.io proposal looks great. Do you have any sense as to whether or when it will be adopted?

Faster the more help we get! As part of my Matasano internship, I've been working on a patch to NSS (Mozilla's crypto library, used by both Firefox and Chrome for TLS) that will give the necessary hooks needed for browsers that use NSS to implement TACK. I'll hopefully be submitting that for review soon (you can see it on bugzilla[1] and fresher in-progress GitHub[2]). At this point, it mostly makes sense for me to f…

"Before Netscape, Barksdale had worked as CEO of McCaw Cellular/AT&T Wireless and, before that, as Vice President and COO of FedEx. [...] President George W. Bush appointed him to the President's Foreign Intelligence Advisory Board."

https://en.wikipedia.org/wiki/Jim_Barksdale

http://www.nytimes.com/2013/07/04/us/monitoring-of-snail-mai...

http://www.mozilla.org/security/announce/2013/mfsa2013-53.ht...

http://www.wired.com/threatlevel/2013/09/freedom-hosting-fbi...

https://www.schneier.com/essay-448.html

https://www.schneier.com/blog/archives/2013/06/blowback_from...

"I generally do not connect to web sites from my own machine, aside from a few sites I have some special relationship with. I fetch web pages from other sites by sending mail to a program (see git://git.gnu.org/womb/hacks.git) that fetches them, much like wget, and then mails them back to me. Then I look at them using a web browser, unless it is easy to see the text in the HTML page directly. I usually try lynx first, then a graphical browser if the page needs it.

I also browse from other people's computers, with their permission. Since I don't identify myself to the sites I visit, this browsing can't be connected with me.

One consequence of this method is that most of the surveillance methods used on the Internet can't see me.

Another consequence is that I never pay for anything on the Web. Anything on the net that requires payment, I don't do.

I would not mind paying for a copy of an e-book or music recording on the Internet if I could do so anonymously, and it were ethical in other ways (no DRM or EULA). But that option almost never exists. I keep looking for ways to make it happen."

http://stallman.org/stallman-computing.html

Re: New NSA Leak Shows MITM Attacks Against Major Internet Services

#142
post #65

Trevor Perrin and I have been working on a dynamic certificate pinning proposal called TACK to help mitigate these types of attacks: http://tack.io In the current state of the world, we're all dependent on CA signatures for each connection we make to a website. TACK is a layer of indirection away from CA certificates, such that we'd only be dependent on CA signatures the very first time we contacted a website. It doe…

I'm _really_ glad that you're out there working on this problem.

Is this any different than certpatrol? And also, what ended up happening to your convergence initiative?

Finally, what do you recommend for individual folks to do in order to protect their SSL traffic?

Thanks again for all the amazing work you do!

Re: New NSA Leak Shows MITM Attacks Against Major Internet Services

#143
post #90
post #65

Trevor Perrin and I have been working on a dynamic certificate pinning proposal called TACK to help mitigate these types of attacks: http://tack.io In the current state of the world, we're all dependent on CA signatures for each connection we make to a website. TACK is a layer of indirection away from CA certificates, such that we'd only be dependent on CA signatures the very first time we contacted a website. It doe…

A point worth making here: antisurveillance technology like TACK does more than make it harder for NSA to MITM TLS. As we've apparently discovered, it also makes it possible for us to detect TLS subversion. It is, right now, a major news story if someone has obtained a malicious root certificate; we need to know when that happens and to which CAs those certs chain (which is discoverable from the certificate). If you…

You make a interesting point in describing TACK as intrusion detection system. It makes sense against larger adversaries, while the MITM protection make more sense against smaller.

The question I have then is, what happen if look at TACK as an IDS. What is its false positive rate? Can it be lowered? Maybe it should inform the website owner as a way to inform both side of the communication that something eerie is happening.

Re: New NSA Leak Shows MITM Attacks Against Major Internet Services

#144
post #103

Earlier quoted context omitted.

Didn't Assange say in a (secretly?) recorded video where he was talking with Schmidt and another person that while the Americans got trusted root keys from Diginotar, the Chinese hacked Verisign and grabbed their root keys? I'll see if I can find the video.

Great tip! It's not exactly what you laid out, but here's the interview you're probably thinking of (ctrl+f verisign): http://wikileaks.org/Transcript-Meeting-Assange-Schmidt Quoting Julian Assange: I have been told actually that VeriSign... has actually given keys to the US government. Not all, but a particular key. Very interesting.

I don't get why everybody talks about Verisign or others giving them "keys". The NSA just need certificates for their own key, right? The only private key that Verisign could give them would be their signing key, which seems much too powerful and central for a signing authority to hand out.

Re: New NSA Leak Shows MITM Attacks Against Major Internet Services

#145

At one point does the NSA become considered a terrorist organization in and of itself? It seems to me that they have stared too long into the abyss.

Terrorists are groups with relatively small power who use dramatic methods. The NSA is quite the opposite; as a governmental organization attached to a very powerful government they would lot be called terriers for their actions, but rather something like totalitarians or tyrants.

Re: New NSA Leak Shows MITM Attacks Against Major Internet Services

#147
post #65

Trevor Perrin and I have been working on a dynamic certificate pinning proposal called TACK to help mitigate these types of attacks: http://tack.io In the current state of the world, we're all dependent on CA signatures for each connection we make to a website. TACK is a layer of indirection away from CA certificates, such that we'd only be dependent on CA signatures the very first time we contacted a website. It doe…

I've been running Firefox with CertPatrol add-on and if there's one take away is that simple client-side pinning generates so much noise that it conditions you into completely ignoring any certificate changes. Way, way too many websites either change their certs regularly or they use a CDN (and sometimes more than one) so that the page ends up getting a different cert on virtually every load. The most obvious example is Twitter's web interface - I am not a heavy user, but I still need to click through a dozen certificate changes per day.

TACK is certainly a must-have and I'm really looking forward it being a native part of browsers, but there will still be likely a lot of (high-profile) websites that won't play along :-/

[0] http://patrol.psyced.org

Re: New NSA Leak Shows MITM Attacks Against Major Internet Services

#148
post #35

Earlier quoted context omitted.

> Right now we need to find out which (root?) CAs are compromised by the NSA. Given that basically all CAs people actually use (even in Europe) are owned by US companies, I would estimate something close to 100% of them have cooperated with the NSA at some point. Obviously there are non-US CAs like China's CNNIC but most of them won't actually sell you a certificate.

If the NSA is doing this "legally" via secret courts etc... Then you have to assume every company subject to US law can't be trusted.

We already know that we can't trust most major US companies. What compromised CAs mean is that we also can't even trust non-US companies due to our dependence on US CAs for TLS to actually be usable.

Re: New NSA Leak Shows MITM Attacks Against Major Internet Services

#149
post #65

Trevor Perrin and I have been working on a dynamic certificate pinning proposal called TACK to help mitigate these types of attacks: http://tack.io In the current state of the world, we're all dependent on CA signatures for each connection we make to a website. TACK is a layer of indirection away from CA certificates, such that we'd only be dependent on CA signatures the very first time we contacted a website. It doe…

I've been running Firefox with CertPatrol add-on and if there's one take away is that simple client-side pinning generates so much noise that it conditions you into completely ignoring any certificate changes. Way, way too many websites either change their certs regularly or they use a CDN (and sometimes more than one) so that the page ends up getting a different cert on virtually every load. The most obvious example…

the way to interpret this situation is to treat high-certificate-churn https sites as though they are plain http. the software UI should communicate "I give up, I can't trust this site anymore" and stop annoying you with attempts to manage the noise
Post reply on HN