Live data from Hacker News

Announcing Keyless SSL

blog.cloudflare.com

181–190 of 190 posts

Re: Announcing Keyless SSL

#181
post #121
post #83

This is a discussion about cyberwarfare in a literal sense. The technical discussion shouldn't really be separated from the economic, political, social and human health concerns because all of those parts of the system interact deeply and directly. A goal of total political cooperation or submission leads to economic sanctions leading to serious human health effects leading to defensive denial of service attacks. Thi…

Would be interested to hear from people who are burying my comment if they have any kind of explanation for why they are doing it, such as counterpoints to my statements. In case there is some insight that I might gain from them, since apparently there is a strong disagreement.

If it is not patently obvious to you that broad ramblings about how "human lives have value", "lethal force is not an acceptable way to resolve conflict", "James Bond fantasy" to "primitive Social Darwinism" (and on and on) have next to no relevance to a discussion about Cloudflare's Keyless SSL implementation, of all things, then I don't know how anybody could ever get through to you to help you understand.

Re: Announcing Keyless SSL

#183

Earlier quoted context omitted.

Now cloudflare employees will have no possible access to the private key, nor do intruders who break into the cloudflare servers. This keeps the bank in full control of who has access to the key, they can stop responding to signing requests at any time and then keep trusting the key on their own servers in the future.

Cloudflare employees will have no access to the key inside a HSM even if it colocated on their premises. That's why you use them. Please summarize the differences between this protocol and PKCS instead of downvoting.

Without a system like this, you would require many HSMs physically co-located with every server around the world, you would be trusting entirely in the ability of the HSM to withstand prolonged physical attack/analysis by a highly-resourced adversary (I'd consider this security suicide), and you would still not have the ability for the bank to cut off impersonation at any moment.

I have, incidentally, downvoted your comment, because you are complaining about downvotes. Don't do that.

Re: Announcing Keyless SSL

#184

Earlier quoted context omitted.

not really -- only in that they are both SSL-related. Free SSL is still in the works. More info soon-ish.

My question was more to the point of: will Keyless SSL work with Free SSL? :)

Not how you're likely thinking. That said, we will use the Keyless technology to expand our data center footprint into locations that we wouldn't feel comfortable storing customers' keys. That will end up benefiting even Free customers who will be faster around the world.

Re: Announcing Keyless SSL

#185
post #163

Earlier quoted context omitted.

Thanks for explaining this. I would also love to read your opinion. Would you be willing to share it in a separate comment? (And hopefully it doesn't incur any downvotes and readers understand it is just an opinion.)

Sure. TL;DR: I think it's mostly useless. From an engineering perspective this is a creative way to circumvent management's requirements ("our encryption keys must be kept on premises"), but otherwise I don't see the value. Let's first see what the problem is with the old method, storing the private key on the Cloudflare server: 1. Cloudflare can read all traffic. 2. Cloudflare can read traffic they can intercept, ev…

> From an engineering perspective this is a creative way to circumvent management's requirements ("our encryption keys must be kept on premises"), but otherwise I don't see the value.

This is a little bit like saying "From an engineering perspective, gold is a good conductor but otherwise I don't see the value."

Whether the desire to avoid sharing SSL keys with 3rd parties stems from management, regulatory or contractual requirements is irrelevant. The bottom line, from CloudFlare's perspective, is that they have been unable to address a significant and potentially highly-profitable market.

Keyless SSL might not be groundbreaking from a technical/engineering perspective but, as a service offering, it could unlock hundreds of millions in revenue for CloudFlare.

Re: Announcing Keyless SSL

#186

Earlier quoted context omitted.

Cloudflare employees will have no access to the key inside a HSM even if it colocated on their premises. That's why you use them. Please summarize the differences between this protocol and PKCS instead of downvoting.

Without a system like this, you would require many HSMs physically co-located with every server around the world, you would be trusting entirely in the ability of the HSM to withstand prolonged physical attack/analysis by a highly-resourced adversary (I'd consider this security suicide), and you would still not have the ability for the bank to cut off impersonation at any moment. I have, incidentally, downvoted your…

A HSM does not need to be physically attached to "every server around the world". This is what they've built here, yet another network attached HSM, but not by following the standard PKCS protocols.

(On the subject of HSM physical attacks: That's another issue altogether, and does not stop at the HSM. But normally that's not an attack you defend against, because you have the relevant contractual obligations against your infrastructure provider.)

I promise not to ask about downvotes again. But the question was honest; if I'm wrong I want to know it.

Re: Announcing Keyless SSL

#187

Earlier quoted context omitted.

Without a system like this, you would require many HSMs physically co-located with every server around the world, you would be trusting entirely in the ability of the HSM to withstand prolonged physical attack/analysis by a highly-resourced adversary (I'd consider this security suicide), and you would still not have the ability for the bank to cut off impersonation at any moment. I have, incidentally, downvoted your…

A HSM does not need to be physically attached to "every server around the world". This is what they've built here, yet another network attached HSM, but not by following the standard PKCS protocols. (On the subject of HSM physical attacks: That's another issue altogether, and does not stop at the HSM. But normally that's not an attack you defend against, because you have the relevant contractual obligations against y…

If there's an established "correct" solution to this problem, why hasn't anyone pointed to it directly, and why didn't the banks use it?

Could you point to some credible expert commentary (as opposed to anonymous noise on HN) describing why what CloudFlare has done here is wrong?

Re: Announcing Keyless SSL

#188

Earlier quoted context omitted.

A HSM does not need to be physically attached to "every server around the world". This is what they've built here, yet another network attached HSM, but not by following the standard PKCS protocols. (On the subject of HSM physical attacks: That's another issue altogether, and does not stop at the HSM. But normally that's not an attack you defend against, because you have the relevant contractual obligations against y…

If there's an established "correct" solution to this problem, why hasn't anyone pointed to it directly, and why didn't the banks use it? Could you point to some credible expert commentary (as opposed to anonymous noise on HN) describing why what CloudFlare has done here is wrong?

Why do you think banks don't use HSMs? They do. They are off the shelf products. If it's the "correct" solution to your problems depends on what your problem actually is.

In this case Cloudflare apparently thought it was the right solution in theory but developed their own instead of using existing products and/or standards. I don't know the rationale for this, but I'd be interesting in knowing more, as you can read in my comment above.

I don't know why I should point out that Cloudflare did the wrong thing. Perhaps you are confusing me with someone else?

What I did say is that the alternative to the described solution is to use a HSM, and that their solution should offer equivalent security.

Re: Announcing Keyless SSL

#189

Earlier quoted context omitted.

If there's an established "correct" solution to this problem, why hasn't anyone pointed to it directly, and why didn't the banks use it? Could you point to some credible expert commentary (as opposed to anonymous noise on HN) describing why what CloudFlare has done here is wrong?

Why do you think banks don't use HSMs? They do. They are off the shelf products. If it's the "correct" solution to your problems depends on what your problem actually is. In this case Cloudflare apparently thought it was the right solution in theory but developed their own instead of using existing products and/or standards. I don't know the rationale for this, but I'd be interesting in knowing more, as you can read…

You said "There is no practical improvement here.".

If CloudFlare has not done something wrong, then why did you say that?

Before you answer that question, remember: A hypothetical solution is not a practical solution. A practical solution is always a practical improvement over the case where there was no existing practical solution offered.

And before you say "They should have used HSMs", remember: CloudFlare has made it clear that HSMs being under their control was simply not an option. It was clear in their first blog post, and just for good measure, it was made absolutely explicit in an interview with Ars[0] where CloudFlare's CEO said "there’s no vault we can ever build that they’ll trust us with their SSL keys".

So, how is there no practical improvement?

[0] http://arstechnica.com/information-technology/2014/09/in-dep...

Re: Announcing Keyless SSL

#190

Earlier quoted context omitted.

Why do you think banks don't use HSMs? They do. They are off the shelf products. If it's the "correct" solution to your problems depends on what your problem actually is. In this case Cloudflare apparently thought it was the right solution in theory but developed their own instead of using existing products and/or standards. I don't know the rationale for this, but I'd be interesting in knowing more, as you can read…

You said "There is no practical improvement here.". If CloudFlare has not done something wrong, then why did you say that? Before you answer that question, remember: A hypothetical solution is not a practical solution . A practical solution is always a practical improvement over the case where there was no existing practical solution offered. And before you say "They should have used HSMs", remember: CloudFlare has m…

That was in response to: "It is a huge improvement. Nobody can impersonate the bank without the bank's cooperation."

And that is not true. The alternative is not to let other organizations impersonate you without your cooperation. That is very clear from the article. Storing plaintext keys with Cloudflare was never on the table. That's not why they built it.

There reasons to why Cloudflare built their own, probably good ones because Cloudflare employs some talented people, and I would think they have to do with the scale Cloudflare operates at.

Network attached HSMs are off the shelf devices. If you've worked with PKI, you've seen them. And that is what they would have went with if they hadn't built this. If it was right or wrong to go with a home-grown HSM instead of an off the shelf one is not something I could possibly know -- but I know it's not a "huge improvement in security" to build your own. The fact that is offers comparable security is probably why the bank chose it.

If there is one thing to take away from the article, it should be: Don't invent your own security protocols. Buy off the shelf devices. If you really need to build your own, this is how.

Post reply on HN