Earlier quoted context omitted.
While a BCP is indication that “nobody cares” is false, it’s pretty far from even a majority of people caring. If BCPs mattered, IP spoofing wouldn’t be an issue on the Internet.
I think the reason the majority doesn’t care is that most people can’t imagine what could happen. They’re reading my WhatsApp messages? So what? I hardly have an answer for that, except for: imagine you’d live in an authoritarian state.
Encrypted web traffic now exceeds 90%
281–290 of 311 posts
Re: Encrypted web traffic now exceeds 90%
#282Nice. Remember the days when IT professionals would exclaim that this was a bad idea? Seems like it's cyclical thing. DNS over HTTPS is now the big bad technology.
> Nice. Remember the days when IT professionals would exclaim that this was a bad idea? It has made some things more difficult. In the old days when I had problems with a remote IMAP server I could watch each command and response going over the wire. It made troubleshooting dead simple. When a POP3 mailbox got hung up on a single huge message you could just telnet in and delete the offending message in a few seconds.…
AFAIK, Wireshark supports decrypting TLS traffic if you give it the private keys.
> When a POP3 mailbox got hung up on a single huge message you could just telnet in
Use “gnutls-cli” or “openssl s_client” – transparent TLS for your terminal. Both those commands also have options supporting protocols’ use of STARTTLS.
Re: Encrypted web traffic now exceeds 90%
#283Earlier quoted context omitted.
Accessing chats from a new device has no technical relation (or constraint) to the lack of end to end encryption. Wire encrypts all chats end to end, and still provides syncing conversations to multiple devices on multiple operating systems. It does limit the sync to the last 30 days, but that’s mostly because of cost reasons rather than technical reasons. Edit/correction: Neither Wire nor Signal sync conversations t…
If you can view your old conversation from a fresh installation on a new devices then this automatically implies that some 3rd party has access to your keys. I.e. your conversion cannot be considered truly private.
Re: Encrypted web traffic now exceeds 90%
#284Earlier quoted context omitted.
Certificate transparency would make it blatantly obvious if Chinese CAs were issuing bogus certificates. (And if they issued certs without submitting them to CT logs they wouldn't be accepted by Chrome or Safari, so it wouldn't be very useful.) Sure, they could do it, but it wouldn't be long until there were no Chinese CAs trusted by any browser.
An attack like this could still be done for CLI clients/library clients such as curl (ie. server-to-server connections), none of which I'm aware of incorporate CT log verification.
All the non-Google modern CT logs moved to rolling annual logs. Cloudflare's Nimbus for example, is actually logs named Nimbus2019, Nimbus2020, Nimbus2021 and so on. Nimbus2019 is for certificates that expire in 2019. Most of them are already expired 'cos it's November already, it doesn't see a lot of updates, in January Cloudflare can freeze that and eventually they can decomission it, browsers will stop trusting it, but it won't matter because those certs already expired. If you go get yourself a new Let's Encrypt cert now, it'll probably be logged with Nimbus2020, come January 2021 you won't care if Cloudflare freezes it and starts shutting it down.
As a result you need frequent (say, monthly seems fine) updates to stay on top of new logs being spun up and old ones shutting down, or else you'll get false positives.
For CLI or server software that has a regular update cadence anyway I can see this as a realistic choice, for a lot of other software it'll be tough to do this without more infrastructure support.
Re: Encrypted web traffic now exceeds 90%
#285Earlier quoted context omitted.
iMessage has several problems: 1. iMessage uses RSA instead of Diffie-Hellman. This means there is no forward secrecy. If the endpoint is compromised at any point, it allows the adversary who has a) been collecting messages in transit from the backbone, or b) in cases where clients talk to server over forward secret connection, who has been collecting messages from the IM server to retroactively decrypt all messages…
Very interesting post, thank you for sharing !! > 2. The RSA key strength is only 1280 bits. This reminds me that in france, unless cryptography is not used for authentication, it is considered a military weapon, and civil usage is restricted in its key strength. Above a certain strength, you technically have to give your key to the government !!...!!! I don't have a source, but fr.wiki [1] says that in 1999, the gov…
Re: Encrypted web traffic now exceeds 90%
#286Earlier quoted context omitted.
I'd almost prefer to be on http knowing I was insecure than be on https and wrongly believing I was secure.
Well, I don't really trust random certs even when they're signed by a respected CA -- but I still prefer using HTTPS. Even if the cert is fraudulent, HTTPS is still encrypting stuff and will protect me from other random attackers. Security is never a binary secure/insecure proposition. There are shades of gray. The key is to use what security you can, but never think "I'm secure now". As an old mentor once told me: t…
Re: Encrypted web traffic now exceeds 90%
#287Earlier quoted context omitted.
I think the reason the majority doesn’t care is that most people can’t imagine what could happen. They’re reading my WhatsApp messages? So what? I hardly have an answer for that, except for: imagine you’d live in an authoritarian state.
I like the explanation that simply explains "privacy": When you are going to the toilet, and everybody knows that your going and what you'll do there, but you still close the door (for the most of us, most of the time).
Like when you’re in high-security areas and have to be monitored in the bathroom there might be a door between you and your guard but no real privacy.
Or when people loudly object to strip-searches at the airport but the scanner that sees everything but then only shows a cutout highlighting suspicious areas to pat down are mostly fine.
Re: Encrypted web traffic now exceeds 90%
#288Earlier quoted context omitted.
Telegram refused to provide decryption keys to Russia, US, China governments. That is great sign to me. Meanwhile Whatsapp has web interface(sic!) where law enforcement agents can request user specific information and probably chat logs for whatever fake reasons they could come up with. Telegram is 300mil users and growing.
Telegram founder also lies a lot. First he says that Telegram developers are not in Russia, out of the FSB reach, but later proofs emerge that they work for Russia from the same office where VK developers worked from. Google Anton Rosenberg and his lawsuit. [1] The public position of Durov ("this man is just crazy freak") is very unconvincing, to say the least. I'd even suspect that it is plausible that Russian autho…
I guess he has to protect his team. US government tried to bribe his programmers to weaken system security.
Re: Encrypted web traffic now exceeds 90%
#289We do need HTTP because sometimes public WiFi networks need you to agree to terms before any requests stop being redirected. I recently found http://neverssl.com That being said those public WiFi’s shouldn’t be redirecting sites in the first place because for HTTPs sites browsers don’t even let you see the page.
http://http.rip
It boggles my mind that we haven't yet agreed on a signaling mechanism at the AP level (DHCP?) for signaling captive portals, as this seems to be quite a common use-case.
Re: Encrypted web traffic now exceeds 90%
#290Earlier quoted context omitted.
Very interesting post, thank you for sharing !! > 2. The RSA key strength is only 1280 bits. This reminds me that in france, unless cryptography is not used for authentication, it is considered a military weapon, and civil usage is restricted in its key strength. Above a certain strength, you technically have to give your key to the government !!...!!! I don't have a source, but fr.wiki [1] says that in 1999, the gov…
TIL that content for wikipedia pages changes per language. I clicked 'English' in the left pane hoping to learn more about what you are saying, but the English version does not have the 'En Europe' section. not so great. Thanks for your post