Seems like a lot of hand wringing over nothing, security is done with huge factors of safety (moving to 256 bit keys when no one had ever broken a 128 or even 96 bit key). It's hard to imagine that 1,2, or even a quarter of the bits couldn't be zero-ed. > it’s easy to think that a difference of 1 single bit would be largely inconsequential when considering numbers this big. In fact, he said, the difference between 26…
In fact, without a practical attack against SHA256, all of the serial number bits could be zeroed. This is undesirable for other reasons, but the serial number isn't part of the cryptographic security of the certificate except as far as it can be used to prevent the person requesting the certificate from anticipating or controlling what the entire signed data will be.
A world of hurt after GoDaddy, Apple, and Google misissue 1M certificates
111–120 of 143 posts
Re: A world of hurt after GoDaddy, Apple, and Google misissue 1M certificates
#112Earlier quoted context omitted.
Nope, the chance of success for each attempt went from 1 in 18,000,000,000,000,000,000 to 2 in 18,000,000,000,000,000,000.
Not 1 in 18 quintillion to 1 in 9 quintillion? I think you've got your binary math wrong.
Re: A world of hurt after GoDaddy, Apple, and Google misissue 1M certificates
#113Ok, I’m all for strong security and better SSL infrastructure, but the response to this issue was just totally overboard. The issue - one fixed bit in a 64-bit randomized serial field - does not compromise the security of these certs in any meaningful way, especially not before their natural expiry dates anyway. The disruption caused by reissuing everything surely exceeded the disruption of this theoretical issue. I…
It's not about whether it compromised security; it's that they didn't adhere to standards. If you're a certificate authority, you need to conform to standards. If you're not, you SHOULD get evicted as an authority, like DigiNotar [1] was for example. [1] https://en.wikipedia.org/wiki/DigiNotar
Re: A world of hurt after GoDaddy, Apple, and Google misissue 1M certificates
#114It's "Rage Culture" or maybe just front-page seeking by the author. The problem with that is that it makes people desensitized because if everyone is screaming all the time, one should just shut their ears. We have real issues to discuss and this isn't one of them by a long shot.
Reducing the search space from 64bits to 63bits is of no consequence because if an attack on 63bits was feasible, it would mean the same attack would work 50% of the time on 64bit (or take twice as long for 100%). That wouldn't be acceptable at all.
Sure, 64>63, but at the very least it's not "A world of hurt"
Re: A world of hurt after GoDaddy, Apple, and Google misissue 1M certificates
#115Earlier quoted context omitted.
Moreover, a Biclique attack against AES exists, by saving some meet-in-the-middle computations, it has already reduced the full 10 rounds, 128-bit AES to "just" 126-bit (25% of 128-bit) of security. Is it a clever attack? Yes. Does it mean the security of AES has been reduced to 25% of the original security level? No. Does it practically matter? No. This is exactly why 128-bit security is seen as a minimum standard i…
Does it mean the security of AES has been reduced to 25% of the original security level? No. I'm curious why that's the case. A plain reading of reducing the security level from 128 to 126 bits would seem to imply the answer is yes?
Re: A world of hurt after GoDaddy, Apple, and Google misissue 1M certificates
#116Earlier quoted context omitted.
Moreover, a Biclique attack against AES exists, by saving some meet-in-the-middle computations, it has already reduced the full 10 rounds, 128-bit AES to "just" 126-bit (25% of 128-bit) of security. Is it a clever attack? Yes. Does it mean the security of AES has been reduced to 25% of the original security level? No. Does it practically matter? No. This is exactly why 128-bit security is seen as a minimum standard i…
Does it mean the security of AES has been reduced to 25% of the original security level? No. I'm curious why that's the case. A plain reading of reducing the security level from 128 to 126 bits would seem to imply the answer is yes?
Re: A world of hurt after GoDaddy, Apple, and Google misissue 1M certificates
#117Earlier quoted context omitted.
Does it mean the security of AES has been reduced to 25% of the original security level? No. I'm curious why that's the case. A plain reading of reducing the security level from 128 to 126 bits would seem to imply the answer is yes?
Because going from "unbreakable in 12 billion years" to "unbreakable in 3 billion years" isn't a practical reduction in security
I get that it’s meaningless - 4x effectively 0 is still effectively 0 - but denying the math doesn’t really help anything.
Re: A world of hurt after GoDaddy, Apple, and Google misissue 1M certificates
#118This article really annoys me. It's "Rage Culture" or maybe just front-page seeking by the author. The problem with that is that it makes people desensitized because if everyone is screaming all the time, one should just shut their ears. We have real issues to discuss and this isn't one of them by a long shot. Reducing the search space from 64bits to 63bits is of no consequence because if an attack on 63bits was feas…
Re: A world of hurt after GoDaddy, Apple, and Google misissue 1M certificates
#119This article really annoys me. It's "Rage Culture" or maybe just front-page seeking by the author. The problem with that is that it makes people desensitized because if everyone is screaming all the time, one should just shut their ears. We have real issues to discuss and this isn't one of them by a long shot. Reducing the search space from 64bits to 63bits is of no consequence because if an attack on 63bits was feas…
Re: A world of hurt after GoDaddy, Apple, and Google misissue 1M certificates
#120This article really annoys me. It's "Rage Culture" or maybe just front-page seeking by the author. The problem with that is that it makes people desensitized because if everyone is screaming all the time, one should just shut their ears. We have real issues to discuss and this isn't one of them by a long shot. Reducing the search space from 64bits to 63bits is of no consequence because if an attack on 63bits was feas…
The problem however as pointed out down-page [0] [1]
> If you can't obey this silly requirement to use extra bits how can we trust you to do all the other things that we need done correctly? Or internally, if you can't make sure you obey this silly rule, how are you making sure you obey these important rules?
> The reason for the urgent fixes is to promote uniformly applied rules. There are certain predefined rules that CAs need to follow, regardless of whether the individual rules help security or not. The rules say the certs that are badly formed need to be reissued in 5 days. > If these rules are not followed and no penalties are applied, then later on when other CAs make more serious mistakes they'll point to this and say "Apple and Google got to disobey the rules, so we should as well, otherwise it's favoritism to Apple and Google."
[0] https://news.ycombinator.com/item?id=19377292 [1] https://news.ycombinator.com/item?id=19375758