Live data from Hacker News

Government-Linked Certificate Authorities in OS X

zitseng.com

71–80 of 88 posts

Re: Government-Linked Certificate Authorities in OS X

#71

> I’ve been sitting on this information for some time, waiting to get more research done before I publish a post. You've been sitting on common knowledge for some time? Research into what? Sorry but this is a very well known issue with HTTPS that has been discussed in depth for the last few years, in particular with people suggesting alternatives and improvements to HTTPS (like certificate pinning, Convergence[0], et…

We keep a running comparison of one such solution (DNSChain) to many other proposals folks have made (including Convergence, Perspectives, Certificate Transparency, DNSSEC, TACK, HPKP):

https://github.com/okTurtles/dnschain/blob/master/docs/Compa...

Re: Government-Linked Certificate Authorities in OS X

#72

Earlier quoted context omitted.

Maybe Google's certificate transparency is what you are looking for? http://www.certificate-transparency.org A more practical approach: Disable all root certificates, then enable them one by one as you are getting browser warnings.

Thank you, I was looking for this. However, in any case, there are already so many CAs, that I am wondering what is preventing governments of forcing one of them to provide a fake certificate that suits their needs for national security reasons...

Certificate Transparency does little to solve this problem. It doesn't stop MITM attacks. It might have a chance of helping a small number of companies that have the resources to monitor all logs, but that's after the attack and only if all relevant CAs are participating in the system. It gives ordinary users nothing and requires sysadmins to go to extreme lengths. Most websites are unlikely to benefit:

https://blog.okturtles.com/2014/09/the-trouble-with-certific...

We've been working very hard on an alternative proposal that prevents MITM attacks called DNSChain, and we keep a running comparison of it with other proposals folks have made here:

https://github.com/okTurtles/dnschain/blob/master/docs/Compa...

Re: Government-Linked Certificate Authorities in OS X

#73
post #26
post #22

I could see another weaker but immediately implementable approach to just issueing a list of domain-root certificate maps that someone would have to manage : Why couldn't browser issue a warning whenever the root CA for a known domain has changed compared to previous browsing sessions ? I suppose MITM attack are targeted and probably depends on the network you're using. If there's a difference between the root certif…

That's what certificate pinning is for. And of course, Chrome already refuses to connect to Google if the certificate doesn't match what Chrome expects. http://tools.ietf.org/html/draft-ietf-websec-key-pinning-12

Pinning has a lot of problems. Copied from our Comparison [1] docs:

Both TACK and HPKP are mechanisms for doing public key pinning for individual websites.

These mechanisms are similar to how SSH uses a known_hosts file to store the fingerprints of public keys it encounters on a "Trust-On-First-Use" ("TOFU") basis.

The problem with these mechanisms is:

* They don't protect on first visit.

* They break websites when the public key needs to legitimately change.

* In the case of TACK, the TACK public key needs to change very frequently (at least every 30 days). This defeats the purpose of pinning, as a MITM does not need to wait long before they can present a fraudulent key that the user has no way to know is legitimate.

* These mechanisms assume that client software has its current time set properly, and they break when that's not true.

While DNSChain does use public key pinning, it doesn't have these problems because there is only one pin that is ever required: the pin to DNSChain itself, which is easily verified once only at setup.

[1] https://github.com/okTurtles/dnschain/blob/master/docs/Compa...

Re: Government-Linked Certificate Authorities in OS X

#75
post #57
post #42

Earlier quoted context omitted.

Not exactly distributed, but it is based on a somewhat different trust model than conventional CAs: https://letsencrypt.org/ It remains to be seen if it actually makes an impact upon launch. It certainly can't replace all the types of certs in use today.

I'm planning on encrypting all my static sites once letsencrypt is available. I don't pass private data (currently) but if it's free why not?

Makes sense to me, and I think this is the future of the web. HTTP will simply cease to be a viable option in the next 3-4 years if cert prices are reduced (or eliminated) and SNI becomes widely available.

Good for Let's Encrypt in taking the initiative to make this happen sooner rather than later.

Re: Government-Linked Certificate Authorities in OS X

#76
post #51

I'm not sure that this is particularly interesting news. For starters, when "the government" wants to spy on you, they generally want to do so in such a way as to not reveal that they are doing so - using their own CA is a big tell that something fishy is going on (yes, only if you have the know-how and inclination to do so, but I'm thinking that this is probably the case for most people trying to keep secrets from t…

I agree, this is not really breaking news. The reality is that any company that wants to operate within the confines of the law can be compelled to work against its purported customers -- no one wants to go to jail because of your website. One nit to pick: obtaining Verisign's root CA key isn't enough to decrypt traffic over the wire. That would just allow Uncle Sam to issue fake certs that appear to be from Verisign…

There isn't any way to solve it. People's fears about the PKI boil down to "if I trust anyone else at all, they might betray me". And yet using encryption without trusting other people is impossible. You aren't going to build your own computer from scratch, for example.

I think our industry needs to collectively move beyond "zomg CA's are pwned by governments". It's just unhelpful. Firstly there's no evidence it's true. A bogus cert would be strong evidence, documents from the Snowden archive talking about compromising CA's would be evidence ..... so far we have zilch.

But even if one day it does happen - what next? You end up down the "what if my CPU is backdoored" rabbit hole. Ultimately you have to ignore adversaries that have unlimited power and focus on the ones that do have limits. There's no other way to stay sane.

Re: Government-Linked Certificate Authorities in OS X

#77

> I’ve been sitting on this information for some time, waiting to get more research done before I publish a post. You've been sitting on common knowledge for some time? Research into what? Sorry but this is a very well known issue with HTTPS that has been discussed in depth for the last few years, in particular with people suggesting alternatives and improvements to HTTPS (like certificate pinning, Convergence[0], et…

If by "tons" you mean, like, once, then sure.

I don't think that's a very helpful way to look at it though. The PKI system has been around for 20 years, was designed to stop credit card theft, and we can sum up the number of times it's been seriously breached on the fingers of one hand.

Many other security systems have failure rates measured in percent, so I don't think it's doing so badly.

Re: Government-Linked Certificate Authorities in OS X

#78

"You think your HTTPS connection is securely encrypted, but wait, couldn’t the U.S. government generate a brand new fake certificate, give it to the NSA, and then serve that to you? Your web browser won’t raise any alarm bells. The SSL certificate is valid, and it is signed by a Certificate Authority that is trusted by your computer." I think it's highly unlikely that they'd do that, as there's a chance that the fake…

Bear in mind they don't actually need to hack or coerce a CA to get them to issue a fake cert. CAs check ownership of a website by either sending an email or doing a regular HTTP request to the website i.e. doing the sort of request that QUANTUM is very good at intercepting and redirecting.

In other words the NSA could MITM the CAwebsite connection and get themselves a cert issued in the regular manner.

However I do not believe they are doing this at any meaningful scale, and possibly not at all. It's clear from the Snowden archives that they focus almost exclusively on malware. That has a lot of advantages for them over creating fake SSL certs.

Also bear in mind that certificate transparency is a multi-year plan to prevent secret issuance of certificates. So there is effort being done to reveal such attacks even before they are happening. Not too shabby!

Re: Government-Linked Certificate Authorities in OS X

#79
post #29

Earlier quoted context omitted.

I'd be interested to know why if you have the time.

The classic manual method of cert pinning is not feasible for more than a handful of large sites, because each browser that supports it has to update its own pin list. Google adds a whitelist of public keys to Chrome upon request, only for high impact sites. Firefox does the same, with a different list. Safari doesn't support it at all. IE supports it in a useless fashion. This is totally unworkable in the long term.…

To give a real example, CryptoCat managed to commit pinning suicide recently. They requested a pin in Chrome and then their CA's intermediate expired, meaning they had to reissue the cert .... but failed, because Chrome rejected the new cert. They had to wait for the next Chrome version to recover and basically had a multi-week outage because of it.

Pinning eliminates CA's by eliminating the agility they provide. Not inherently an awesome deal.

Re: Government-Linked Certificate Authorities in OS X

#80

Earlier quoted context omitted.

Maybe Google's certificate transparency is what you are looking for? http://www.certificate-transparency.org A more practical approach: Disable all root certificates, then enable them one by one as you are getting browser warnings.

Thank you, I was looking for this. However, in any case, there are already so many CAs, that I am wondering what is preventing governments of forcing one of them to provide a fake certificate that suits their needs for national security reasons...

What "stops" them (to the extent that anything stops a government that is ignoring their own laws) is that the agreements CAs sign with browser/OS makers don't have any provision for issuing fake certs just because a government requested it or compromised the key.

That means if anyone found evidence that a CA was issuing bogus certs (such as one of those certs), that CA would be revoked and bankruptcy would follow soon after. The fact that they were just obeying a court order wouldn't be considered relevant by the browser makers, especially if it's an obscure and little used one.

There are other forms of punishment beyond outright revocation. A CA owned by the French government did something bad at some point (I forgot what), and instead of total revocation they were name constrained to .fr

But basically, forcing CAs to co-operate with you against the contracts they've signed is a very limited strategy. Most governments outside the US government can only do it once or twice before there are no more CAs left in their jurisdiction. Not to mention the legal mess that would result from a company beyond forced to commit suicide to help an intercept operation.

Post reply on HN