Live data from Hacker News

Symantec Issues Intermediate CA Certificate for Blue Coat Public Services

crt.sh

101–110 of 118 posts

Re: Symantec Issues Intermediate CA Certificate for Blue Coat Public Services

#101

Earlier quoted context omitted.

If you have a problem with that, use your own network.

What if the site they're connecting to has a problem with that? If I for example serve E-Healthcare records, and have an agreement that a given person that I have vetted has access to them, I might have a problem with your unvetted IT staff having access but how would I know?

Sounds like you have a contract problem with the vetted individual.

Re: Symantec Issues Intermediate CA Certificate for Blue Coat Public Services

#102
post #15

Earlier quoted context omitted.

Yes they have a cloud service: https://www.bluecoat.com/products-and-solutions/global-cloud... In fact, other than running a legit CA service, using this intermediate CA to intercept and decrypt traffic on their cloud is the only acceptable use of the intermediate CA I can think of, as long as they disclose to their cloud customers that they MitM TLS connections. After all, Blue Coat's cloud is their network, so they…

It's acceptable (albeit a terrible practice) to MITM traffic on your own network. It's not at all acceptable for any CA certificate accepted by default in all browsers (not just those on your network), no matter whether root or intermediate, to ever issue a certificate for a domain to anyone other than the owner of that domain. Issuing such a certificate is grounds for immediate revocation of browser trust. If you wa…

I'd argue that it doesn't give ample warning. I've seen a number of corporate networks where a MITM trusted root cert is installed on machines via an AD policy and the end users have no clue that their IT department can see things like their banking passwords. Unless you examine the cert by hand or connect a device without the cert to the network, you would have no idea this is going on.

Re: Symantec Issues Intermediate CA Certificate for Blue Coat Public Services

#103

Earlier quoted context omitted.

They have a cloud services platform, perhaps it's for that? Symantec would get destroyed if they issued a CA cert that was misused, right? Edit: This product says it does real-time traffic analysis for user transactions. It's understandable they want to make this as easy for customers as possible, just like CloudFlare. https://www.elastica.net/cloudsoc/-- or maybe I'm misunderstanding what it does?

Security is not obtained by optimistically assuming actors are using their capabilities for good. Sure, there are legit ways they could use this, but the entire point of CAs is that they be trusted actors, and there are very strong reasons not to trust Blue Coat. Your comment is like discovering the fox has been given the keys to the henhouse and saying "Maybe the fox just wants to hang out with the hens".

It is now simply a matter of time. How long will it take to find out that this certificate was used for a MITM attack?

I suspect it will be less than 18 months. And 99% of the people will be 'shocked' :-)

Re: Symantec Issues Intermediate CA Certificate for Blue Coat Public Services

#104

Earlier quoted context omitted.

Even Cloudflare doesn't use their own CA, but they have a relationship with Comodo; at least, from what I can tell on services I use with Cloudflare. If they just need to issue lots of certificates, or make it easy for client devices to get certificates, or even for their own cloud services, they could use LetsEncrypt. There are very few use cases where having your own CA is necessary, and for a company like Blue Coa…

We have relationships with Comodo, DigiCert, and GlobalSign. A large part of our Universal SSL issuance is currently through Comodo, which is probably what you noticed. (We've considered acquiring our own CA or subCA in the past but the audit requirements are quite onerous, at least after the first year, and sometimes it's nice to have someone handle certain aspects for you.) The most important thing to pay attention…

"I think these audits are released to the public as I remember Let's Encrypt doing so, but that may just be because i) they aren't a full blown directly browser trusted CA or ii) LE just decided to do so as it fits their ethos."

Head of Let's Encrypt here. We're required to publicly disclose our annual audit reports, as are all publicly trusted CAs.

No comment on this particular situation since I don't know enough about it, but I'd expect any organization with a publicly trusted intermediate to have a CP/CPS publicly available prior to getting the intermediate.

Re: Symantec Issues Intermediate CA Certificate for Blue Coat Public Services

#105
post #83

Earlier quoted context omitted.

How did we allow a single company to own 30% of a market, despite its expensive pricing ( https://www.symantec.com/en/uk/theme.jsp?themeid=compare-ssl... )? Comodo and Synantec are 32% each, then goes others. StartSSl is significant but 2%, Let'sEncrypt tiny for now: https://w3techs.com/technologies/history_overview/ssl_certif...

I'm not able to find the methodology for the w3techs report, but I suspect they only count the ultimate root, not any intermediates. Let's Encrypt's root is not trusted by any browser yet, so they got a cross-signature from IdenTrust. So far, basically everybody using Let's Encrypt chains to the IdenTrust root. Given that IdenTrust grew from " https://letsencrypt.org/stats/ , I strongly suspect that the 5.6% market s…

"Given that IdenTrust grew from "https://letsencrypt.org/stats/ , I strongly suspect that the 5.6% market share credited to IdenTrust actually belongs to Let's Encrypt."

This is correct. (Source: I run Let's Encrypt)

Re: Symantec Issues Intermediate CA Certificate for Blue Coat Public Services

#106
post #45

Earlier quoted context omitted.

I'm good with my work or school owned/issued device trusting a root cert installed by that device's owner. I'm _not good with a school or employer's network being able to generate arbitrary certs for my email, bank, social networks, etc - WITHOUT ME KNOWING ABOUT IT ON MY PERSONAL DEVICES... Sure, MitM me if it's your network - but I 100% should be able to rely on my browser on my device reliably being able to tell m…

If you have a problem with that, use your own network.

I agree that people running the network have the right to run it as they want.

But if an attack can work on you using my network, it is also an attack that works on me surreptitiously rerouting your traffic onto my network. Basically undoing HTTPS.

Re: Symantec Issues Intermediate CA Certificate for Blue Coat Public Services

#107
post #36
post #22

Earlier quoted context omitted.

> In all likelihood it's to allow Blue Coat to roll out a service that allows it to create certificates for clients of its security services. Any deviation from that CPS would necessitate revoking this intermediate certificate. So why doesn't Blue Coat establish their own CA for this purpose?

Are you saying they should become a new root CA? That is a huge amount of work, and would require them to convince all browsers and OS's to make them a root CA, which many would be reluctant to do.

No, it would require them to add their cert on the intended machines under their control. The only reasons they would need the trust of all browsers and OS's are subterfuge and laziness. They should not be globally trusted to issue certificates.

Re: Symantec Issues Intermediate CA Certificate for Blue Coat Public Services

#108

Earlier quoted context omitted.

Do you see no value in SSL at all, then?

As a private network owner, I see risk in uncontrolled SSL. If you provide a publicly accessible "Guest" network isolated from my corporate or private resources, that I agree that it's unreasonable to intercept TLS sessions. If you are on my network, which exists to serve my constituents with a personal device, I have every right to or even have a duty to ensure that you aren't threatening the overall integrity of th…

The objection is not to controlling TLS on a private network. The objection is to using a method that can silently intercept connections to devices you don't administrate.

If someone doesn't want to install the root cert, then "use your own network" is a perfectly fine response.

If someone is upset that the TLS security model is broken in half, then "use your own network" is not a valid response.

Re: Symantec Issues Intermediate CA Certificate for Blue Coat Public Services

#109

Earlier quoted context omitted.

If you have a problem with that, use your own network.

I agree that people running the network have the right to run it as they want. But if an attack can work on you using my network, it is also an attack that works on me surreptitiously rerouting your traffic onto my network. Basically undoing HTTPS.

The scope is broader than an attack.

Also, what I'm talking about (MITM proxy on a private network), it's not sneaky -- you will get unsigned cert warnings. If you are using an employers device, you won't see warnings, but can examine the SSL certificate. You should also assume that you are being monitored.

Re: Symantec Issues Intermediate CA Certificate for Blue Coat Public Services

#110
post #93

Earlier quoted context omitted.

Blue Coat can trivially work around this limitation by placing the intermediate cert on a server. Now when the traffic inspection device wants a (leaf) cert, it calls home to the server and the server provides it.

Seems like it would have unacceptable performance limitations.

That's your source of security? Performance limitations?

I'm not even convinced it would have performance limitations. Let's say Alice and Bob are communicating and Eve has the BlueCoat device in the middle. Alice sends the initial connection request to Bob, but Eve gets it instead. Eve then sends a new initial request to Bob AND a request to the BlueCoat server to get the fake cert in parallel. As long as the BlueCoat server responds with similar latency to Bob, Alice won't see any significant difference in latency as compared to Eve simply forwarding the requests.

Post reply on HN