Live data from Hacker News

Netgear Signed TLS Cert Private Key Disclosure

gist.github.com

1–10 of 158 posts

Re: Netgear Signed TLS Cert Private Key Disclosure

#2
6 days is nowhere near a justifiable timeframe for full disclosure.

Even if you disagree with that, you should have first reported Key Compromises to Entrust and Comodo before publicly posting the private keys. They are bound by BRs and their own CPS to revoke certificates such as this one - and they would have done so promptly.

This is not what you should do as a security researcher - delete the gist until the CAs have a chance to revoke it via OCSP.

Re: Netgear Signed TLS Cert Private Key Disclosure

#5
post #2

6 days is nowhere near a justifiable timeframe for full disclosure. Even if you disagree with that, you should have first reported Key Compromises to Entrust and Comodo before publicly posting the private keys. They are bound by BRs and their own CPS to revoke certificates such as this one - and they would have done so promptly. This is not what you should do as a security researcher - delete the gist until the CAs h…

I think in this case it's to force browser vendors (who have the most exploitable endpoints) and companies like Apple and Microsoft at the OS level, to blacklist the offending certs.

Though the CAs in question should probably have an automated challenge-response system to which a timed signed reply of a given message of their choice causes a revocation of the key that signed the message. (As sufficient proof of "this is vuln, kill it now, ask questions after".)

Re: Netgear Signed TLS Cert Private Key Disclosure

#6
post #4
post #3

Can anyone make out what the funjsq.com is about?

Chinese gaming VPN service or something, bypasses China IP blocks to allow them to play on NA/EU servers.

I'm wondering why such a VPN service is included in the netgear firmware image? Wouldn't this resonate negatively with Chinese authorities?

Re: Netgear Signed TLS Cert Private Key Disclosure

#7
post #5
post #2

6 days is nowhere near a justifiable timeframe for full disclosure. Even if you disagree with that, you should have first reported Key Compromises to Entrust and Comodo before publicly posting the private keys. They are bound by BRs and their own CPS to revoke certificates such as this one - and they would have done so promptly. This is not what you should do as a security researcher - delete the gist until the CAs h…

I think in this case it's to force browser vendors (who have the most exploitable endpoints) and companies like Apple and Microsoft at the OS level, to blacklist the offending certs. Though the CAs in question should probably have an automated challenge-response system to which a timed signed reply of a given message of their choice causes a revocation of the key that signed the message. (As sufficient proof of "this…

Did this researcher even contact the CAs? Generally, they're pretty responsive and will revoke quickly; there are CA/Browser forum guidelines that address this; if nothing else, you can send them the private key to prove possession.

Re: Netgear Signed TLS Cert Private Key Disclosure

#8
post #6
post #4

Earlier quoted context omitted.

Chinese gaming VPN service or something, bypasses China IP blocks to allow them to play on NA/EU servers.

I'm wondering why such a VPN service is included in the netgear firmware image? Wouldn't this resonate negatively with Chinese authorities?

Unless it was mandated/deployed by a state actor, looking to MITM/monitor VPN users within the country?

Re: Netgear Signed TLS Cert Private Key Disclosure

#9
post #5
post #2

6 days is nowhere near a justifiable timeframe for full disclosure. Even if you disagree with that, you should have first reported Key Compromises to Entrust and Comodo before publicly posting the private keys. They are bound by BRs and their own CPS to revoke certificates such as this one - and they would have done so promptly. This is not what you should do as a security researcher - delete the gist until the CAs h…

I think in this case it's to force browser vendors (who have the most exploitable endpoints) and companies like Apple and Microsoft at the OS level, to blacklist the offending certs. Though the CAs in question should probably have an automated challenge-response system to which a timed signed reply of a given message of their choice causes a revocation of the key that signed the message. (As sufficient proof of "this…

The OS level actions won't be fast. So this disclosure is closer to an irresponsible attitude. At least CAs should be informed.

Re: Netgear Signed TLS Cert Private Key Disclosure

#10
The HTTPS cert is used for the router's login page - apparently putting an IP address on the box backside label confuses too many people. It makes sense to put it behind HTTPS because the browser will whine "this page is insecure"... but how is a router vendor supposed to include the neccessary certificate that won't get leaked?

The only thing I can imagine here is a dedicated HSM chip... but that's overkill for a 10$ router?

Post reply on HN