Live data from Hacker News

Launching in 2015: A Certificate Authority to Encrypt the Entire Web

eff.org

461–470 of 476 posts

Re: Launching in 2015: A Certificate Authority to Encrypt the Entire Web

#461

Earlier quoted context omitted.

>> Encrypted (Certified) COOL GREEN > I think we can agree that this case is correct. If you have a properly vetted cert, more power to you. The browser should tell your users that you do own this domain. Maybe. I just checked my browser and it already trusts more than 100 certificate authorities from all around the world, including some companies that I don't trust, some governments that I don't trust, but mainly co…

The problem here is that getting a vetted cert - or worse, compromising the authority that vets those certs is relatively trivial for a nation state, or even someone that's morally compromised enough to say, kidnap the CA Director's family. The fact is, trust is easily compromised and the current infrastructure needs to be hardened against that. Even if the browser only had a single authority you do trust... how easy…

> Even if the browser only had a single authority you do trust... how easy would it be for someone to force them to do something to compromise your trust? For instance with an NSL bound with a gag order?

By having several authorities you do trust? Preferably in different jurisdictions and parts of the world. But only those who you do trust.

Re: Launching in 2015: A Certificate Authority to Encrypt the Entire Web

#462
post #423
post #416

Wouldn't this result in putting all the eggs in a single basket ? Beside, as an European, I'm not so excited that such initiative is under control of American Law. I suspect that American interests will prevail.

Would you like to spell out more explicitly which effects of U.S. jurisdiction you're most concerned with? I agree that there are several possible effects of jurisdiction on CAs that people could reasonably be concerned with (whether as would-be certificate requestors or would-be relying parties), but I'm wondering which ones are concerning you most.

The effect is that the NSA, the FBI or others could obtain the private key of the EFF root CA through legal arm twisting and gagging.

Certificates are public, so there is no problem with certificate request.

If the project is US only, than it won't make much difference with the actual situation. It wasn't explicit in the announcement.

Re: Launching in 2015: A Certificate Authority to Encrypt the Entire Web

#463
Even today you can have all your HTTP traffic encrypted and compressed, using Mozilla Janus[1] or Data Compression Proxy[2].

[1] https://addons.mozilla.org/en-US/firefox/addon/janus-proxy-c...

[2] https://chrome.google.com/webstore/detail/data-compression-p...

Re: Launching in 2015: A Certificate Authority to Encrypt the Entire Web

#464

Earlier quoted context omitted.

You might want to read up on what an NSL actually is, since you and the GP are clearly very confused.

Explain, please. What prevents an NSL from compelling Google from minting a new certificate (they are a CA), providing the keys to the bad guys, and distributing that certificate in Chrome? NSLs have been used in the past to compel positive action (c.f. Lavabit), so I really don't see how you think there's any practical limit to their power. My understanding is that there isn't a limit. If I am wrong about this, then…

An NSL can be used only to compel release of connection or transaction metadata, and cannot be used to compel disclosure of message contents. It's basically a fast-track for getting things like call records, and it most emphatically cannot be used to compel turning over a certificate or allowing a man-in-the-middle.

To my knowledge the exact details of the Lavabit case were never released, but from what has been released it's quite clear that the issue was regarding a warrant and a gag order, because the ensuing litigation wouldn't have been remotely applicable to an NSL (otherwise Lavabit's attorney would have won on a walk).

None of this is to say that I think NSLs should exist. In fact, I think they're a terrible idea. But the vast majority of discussions around them and similar topics is so grossly uninformed that it's impossible to take most people seriously on these subjects.

Re: Launching in 2015: A Certificate Authority to Encrypt the Entire Web

#465

Looking at the spec [0] I'm concerned about the section on 'Recovery Tokens'. "A recovery token is a fallback authentication mechanism. In the event that a client loses all other state, including authorized key pairs and key pairs bound to certificates, the client can use the recovery token to prove that it was previously authorized for the identifier in question. This mechanism is necessary because once an ACME serv…

It's possible that this question shouldn't be decided one way or another in the specification, since it will ultimately be more a matter of CA policy about how the CA wants to handle automated issuance and risks.

Re: Launching in 2015: A Certificate Authority to Encrypt the Entire Web

#466

Looking at the spec [0] I'm concerned about the section on 'Recovery Tokens'. "A recovery token is a fallback authentication mechanism. In the event that a client loses all other state, including authorized key pairs and key pairs bound to certificates, the client can use the recovery token to prove that it was previously authorized for the identifier in question. This mechanism is necessary because once an ACME serv…

This is a question about the policy layer of the CA using the ACME protocol.

The previous issuing CA should have revoked the cert they issued when the domain was transferred. But a CA speaking the ACME protocol might choose to look at whois and DNS for additional information to decide whether it issues different challenges in response to a certification request.

Re: Launching in 2015: A Certificate Authority to Encrypt the Entire Web

#467
post #428
post #202

Earlier quoted context omitted.

I just bought a cert on Saturday for $9. It's less than the domain name.

$9 is a big step up from free, which is what the rest of my blog costs.

Is your blog a .tk site? Where else would you get a free domain?

Re: Launching in 2015: A Certificate Authority to Encrypt the Entire Web

#468

Earlier quoted context omitted.

Because encryption with SSL without trust of the SSL cert is meaningless. It might as well be not encrypted.

I wonder if this is true. If there's a man in the middle, then they can read the traffic. But others still have a problem. With HTTP, you know that everyone can read the traffic. I think unsigned certs, especially with pinning, can be used to make wholesale collection of internet traffic vastly more difficult.

Now you are talking about obscurity, not security. In my opinion.

Re: Launching in 2015: A Certificate Authority to Encrypt the Entire Web

#469

Earlier quoted context omitted.

Explain, please. What prevents an NSL from compelling Google from minting a new certificate (they are a CA), providing the keys to the bad guys, and distributing that certificate in Chrome? NSLs have been used in the past to compel positive action (c.f. Lavabit), so I really don't see how you think there's any practical limit to their power. My understanding is that there isn't a limit. If I am wrong about this, then…

An NSL can be used only to compel release of connection or transaction metadata, and cannot be used to compel disclosure of message contents. It's basically a fast-track for getting things like call records, and it most emphatically cannot be used to compel turning over a certificate or allowing a man-in-the-middle. To my knowledge the exact details of the Lavabit case were never released, but from what has been rele…

Okay, so not an NSL. Incorrect terminology pointing at the same awful effect, an unaccountable court issuing unchallengeable rulings that cannot be discussed.

No substantial difference from the concept I'm complaining about.

Re: Launching in 2015: A Certificate Authority to Encrypt the Entire Web

#470
post #396

Earlier quoted context omitted.

There are no such attackers.

You're saying that everyone able and willing to passively snoop, is also able and willing to compromise the channel and mimic the server?

Correct.
Post reply on HN