This is a discussion about cyberwarfare in a literal sense. The technical discussion shouldn't really be separated from the economic, political, social and human health concerns because all of those parts of the system interact deeply and directly. A goal of total political cooperation or submission leads to economic sanctions leading to serious human health effects leading to defensive denial of service attacks. Thi…
Would be interested to hear from people who are burying my comment if they have any kind of explanation for why they are doing it, such as counterpoints to my statements. In case there is some insight that I might gain from them, since apparently there is a strong disagreement.
Announcing Keyless SSL
141–150 of 190 posts
Re: Announcing Keyless SSL
#142Earlier quoted context omitted.
As Google and Yahoo will tell you after they found out the US government broke into their dedicated lines between data centers... No. It must be encrypted at every transfer without exception.
There's a huge difference between passively tapping a fiber optic cable and infiltrating a network to inject malicious traffic. All we've ever seen evidence of is NSA's passive tapping of Google & others.
Re: Announcing Keyless SSL
#143This is a discussion about cyberwarfare in a literal sense. The technical discussion shouldn't really be separated from the economic, political, social and human health concerns because all of those parts of the system interact deeply and directly. A goal of total political cooperation or submission leads to economic sanctions leading to serious human health effects leading to defensive denial of service attacks. Thi…
Would be interested to hear from people who are burying my comment if they have any kind of explanation for why they are doing it, such as counterpoints to my statements. In case there is some insight that I might gain from them, since apparently there is a strong disagreement.
Re: Announcing Keyless SSL
#144Earlier quoted context omitted.
Now you don't want to hand over this private key to Cloudflare if you don't need to, because then they can read all traffic. Generally the key you would give them is for, and limited to, the resources that they cache/reverse proxy, so the same "read all traffic" concern exists. What Cloudflare did is essentially, as others have mentioned, PKCS11 over the internet. PKCS11 is an existing, very well proven technique of…
It is very obvious... In hindsight?
You'd think if this was a known technique, the mentioned banks would already have been asking for it, implementing it, or doing it.
Personally, I think CloudFlare is one of the few companies on here doing innovating stuff, and solving real issues.
And if not - if they've pulled the wool over my eyes - then at least I can respect their marketing.
Re: Announcing Keyless SSL
#145Re: Announcing Keyless SSL
#146Earlier quoted context omitted.
No disrespect meant, but from a security perspective the idea of patching security-critical software with a patch from a stranger on the Internet is kind of crazy, isn't it?
Though Fedor isn't just some complete stranger online.
Re: Announcing Keyless SSL
#147Not to say that it's not useful, but the article describes it as some grand invention.
Re: Announcing Keyless SSL
#148Earlier quoted context omitted.
So if someone breaks into a CloudFlare server, can they steal the CloudFlare private key and then make unlimited numbers of requests against the e.g. bank's oracle? Aren't you now still depending on certificate revocation but have just shifted the problem downstream (it is now the bank's job to revoke you, rather than the user's browser's job). Or do you yourselves use "Keyless" technology, so that CloudFlare servers…
Breaking into a CloudFlare server does not get you this private key. CloudFlare does not keep this authentication key unencrypted on disk.
Re: Announcing Keyless SSL
#149Earlier quoted context omitted.
But it's already fairly obvious how it works. They essentially MITM with the keyserver to receive the SSL nonce. Of course, it's pretty silly to expect cloudflare to have some special mathematical revolution to solve the stated problem. In fact I figure if you could terminate SSL without an online private key, the encryption scheme is simply broken.
But it's already fairly obvious how it works. It is obvious, and they effectively implemented a custom approach for PKCS11/ssh-agent. Yet the narrative implies some brilliant period of insight and innovation, when really it kind of isn't. Which is where the "silly" notion that they must have did something novel came from -- their narrative claims it.
Re: Announcing Keyless SSL
#150While this is a cool feature, I wouldn't say the improvement is more than marginal: all potentially sensitive customer data is still available to Cloudflare in plain text. And after all, with a Business plan you can already use your own ("custom") SSL certificate which you can then revoke at any time. Why not offer a "pass through" mode where the proxying is done on the network layer rather than the application layer…
Well, for the use case given, with "Keyless SSL", if Cloudflare is compromised, then the bank doesn't need to report the incident to the Federal Reserve. But yes, users' plaintexts would still be compromised. "Security theatre" indeed.
> An institution should notify its primary Federal regulator as soon
> as it becomes aware of the unauthorized access to or misuse of
> sensitive customer information or customer information systems.
FDIC: Supervisory Insights https://www.fdic.gov/regulations/examinations/supervisory/in...