This is a discussion about cyberwarfare in a literal sense. The technical discussion shouldn't really be separated from the economic, political, social and human health concerns because all of those parts of the system interact deeply and directly. A goal of total political cooperation or submission leads to economic sanctions leading to serious human health effects leading to defensive denial of service attacks. Thi…
Would be interested to hear from people who are burying my comment if they have any kind of explanation for why they are doing it, such as counterpoints to my statements. In case there is some insight that I might gain from them, since apparently there is a strong disagreement.
Announcing Keyless SSL
181–190 of 190 posts
Re: Announcing Keyless SSL
#182Re: Announcing Keyless SSL
#183Earlier quoted context omitted.
Now cloudflare employees will have no possible access to the private key, nor do intruders who break into the cloudflare servers. This keeps the bank in full control of who has access to the key, they can stop responding to signing requests at any time and then keep trusting the key on their own servers in the future.
Cloudflare employees will have no access to the key inside a HSM even if it colocated on their premises. That's why you use them. Please summarize the differences between this protocol and PKCS instead of downvoting.
I have, incidentally, downvoted your comment, because you are complaining about downvotes. Don't do that.
Re: Announcing Keyless SSL
#184Earlier quoted context omitted.
not really -- only in that they are both SSL-related. Free SSL is still in the works. More info soon-ish.
My question was more to the point of: will Keyless SSL work with Free SSL? :)
Re: Announcing Keyless SSL
#185Earlier quoted context omitted.
Thanks for explaining this. I would also love to read your opinion. Would you be willing to share it in a separate comment? (And hopefully it doesn't incur any downvotes and readers understand it is just an opinion.)
Sure. TL;DR: I think it's mostly useless. From an engineering perspective this is a creative way to circumvent management's requirements ("our encryption keys must be kept on premises"), but otherwise I don't see the value. Let's first see what the problem is with the old method, storing the private key on the Cloudflare server: 1. Cloudflare can read all traffic. 2. Cloudflare can read traffic they can intercept, ev…
This is a little bit like saying "From an engineering perspective, gold is a good conductor but otherwise I don't see the value."
Whether the desire to avoid sharing SSL keys with 3rd parties stems from management, regulatory or contractual requirements is irrelevant. The bottom line, from CloudFlare's perspective, is that they have been unable to address a significant and potentially highly-profitable market.
Keyless SSL might not be groundbreaking from a technical/engineering perspective but, as a service offering, it could unlock hundreds of millions in revenue for CloudFlare.
Re: Announcing Keyless SSL
#186Earlier quoted context omitted.
Cloudflare employees will have no access to the key inside a HSM even if it colocated on their premises. That's why you use them. Please summarize the differences between this protocol and PKCS instead of downvoting.
Without a system like this, you would require many HSMs physically co-located with every server around the world, you would be trusting entirely in the ability of the HSM to withstand prolonged physical attack/analysis by a highly-resourced adversary (I'd consider this security suicide), and you would still not have the ability for the bank to cut off impersonation at any moment. I have, incidentally, downvoted your…
(On the subject of HSM physical attacks: That's another issue altogether, and does not stop at the HSM. But normally that's not an attack you defend against, because you have the relevant contractual obligations against your infrastructure provider.)
I promise not to ask about downvotes again. But the question was honest; if I'm wrong I want to know it.
Re: Announcing Keyless SSL
#187Earlier quoted context omitted.
Without a system like this, you would require many HSMs physically co-located with every server around the world, you would be trusting entirely in the ability of the HSM to withstand prolonged physical attack/analysis by a highly-resourced adversary (I'd consider this security suicide), and you would still not have the ability for the bank to cut off impersonation at any moment. I have, incidentally, downvoted your…
A HSM does not need to be physically attached to "every server around the world". This is what they've built here, yet another network attached HSM, but not by following the standard PKCS protocols. (On the subject of HSM physical attacks: That's another issue altogether, and does not stop at the HSM. But normally that's not an attack you defend against, because you have the relevant contractual obligations against y…
Could you point to some credible expert commentary (as opposed to anonymous noise on HN) describing why what CloudFlare has done here is wrong?
Re: Announcing Keyless SSL
#188Earlier quoted context omitted.
A HSM does not need to be physically attached to "every server around the world". This is what they've built here, yet another network attached HSM, but not by following the standard PKCS protocols. (On the subject of HSM physical attacks: That's another issue altogether, and does not stop at the HSM. But normally that's not an attack you defend against, because you have the relevant contractual obligations against y…
If there's an established "correct" solution to this problem, why hasn't anyone pointed to it directly, and why didn't the banks use it? Could you point to some credible expert commentary (as opposed to anonymous noise on HN) describing why what CloudFlare has done here is wrong?
In this case Cloudflare apparently thought it was the right solution in theory but developed their own instead of using existing products and/or standards. I don't know the rationale for this, but I'd be interesting in knowing more, as you can read in my comment above.
I don't know why I should point out that Cloudflare did the wrong thing. Perhaps you are confusing me with someone else?
What I did say is that the alternative to the described solution is to use a HSM, and that their solution should offer equivalent security.
Re: Announcing Keyless SSL
#189Earlier quoted context omitted.
If there's an established "correct" solution to this problem, why hasn't anyone pointed to it directly, and why didn't the banks use it? Could you point to some credible expert commentary (as opposed to anonymous noise on HN) describing why what CloudFlare has done here is wrong?
Why do you think banks don't use HSMs? They do. They are off the shelf products. If it's the "correct" solution to your problems depends on what your problem actually is. In this case Cloudflare apparently thought it was the right solution in theory but developed their own instead of using existing products and/or standards. I don't know the rationale for this, but I'd be interesting in knowing more, as you can read…
If CloudFlare has not done something wrong, then why did you say that?
Before you answer that question, remember: A hypothetical solution is not a practical solution. A practical solution is always a practical improvement over the case where there was no existing practical solution offered.
And before you say "They should have used HSMs", remember: CloudFlare has made it clear that HSMs being under their control was simply not an option. It was clear in their first blog post, and just for good measure, it was made absolutely explicit in an interview with Ars[0] where CloudFlare's CEO said "there’s no vault we can ever build that they’ll trust us with their SSL keys".
So, how is there no practical improvement?
[0] http://arstechnica.com/information-technology/2014/09/in-dep...
Re: Announcing Keyless SSL
#190Earlier quoted context omitted.
Why do you think banks don't use HSMs? They do. They are off the shelf products. If it's the "correct" solution to your problems depends on what your problem actually is. In this case Cloudflare apparently thought it was the right solution in theory but developed their own instead of using existing products and/or standards. I don't know the rationale for this, but I'd be interesting in knowing more, as you can read…
You said "There is no practical improvement here.". If CloudFlare has not done something wrong, then why did you say that? Before you answer that question, remember: A hypothetical solution is not a practical solution . A practical solution is always a practical improvement over the case where there was no existing practical solution offered. And before you say "They should have used HSMs", remember: CloudFlare has m…
And that is not true. The alternative is not to let other organizations impersonate you without your cooperation. That is very clear from the article. Storing plaintext keys with Cloudflare was never on the table. That's not why they built it.
There reasons to why Cloudflare built their own, probably good ones because Cloudflare employs some talented people, and I would think they have to do with the scale Cloudflare operates at.
Network attached HSMs are off the shelf devices. If you've worked with PKI, you've seen them. And that is what they would have went with if they hadn't built this. If it was right or wrong to go with a home-grown HSM instead of an off the shelf one is not something I could possibly know -- but I know it's not a "huge improvement in security" to build your own. The fact that is offers comparable security is probably why the bank chose it.
If there is one thing to take away from the article, it should be: Don't invent your own security protocols. Buy off the shelf devices. If you really need to build your own, this is how.