Live data from Hacker News

The Power to Revoke Lies with the Certificate Authority

scotthelme.co.uk

51–60 of 89 posts

Re: The Power to Revoke Lies with the Certificate Authority

#51

There are several points in this post but the bulk of it is, I feel, one of those classic fallacies that journalists or security hobbyists often engage in: "I found what looks like a flaw in a system but I didn't try to exploit it for real, look how clever I am" So his mate registered a company with the same name as another company and got an EV cert. Well done. Everyone knew that was possible already, at least every…

"If he had been, and had used that EV cert to phish Stripe customers, he'd have been reported to the police using the details from the CA and possibly prosecuted. Bear in mind he had to register a company in the USA, not Kazakhstan."

Are you _from_ the USA? Or do you believe its propaganda from outside?

You don't need to even be able to point to the USA on a map to set up a US company and do all this paperwork. You fill out a few forms on a web page, pay a little bit of money, American lawyers sort everything else out. They keep some of the money, the State keeps the rest, everybody is happy. Oh, except your victims. They can call the cops of course, but the State obeyed the law, and the Lawyer just does paperwork. It's not a crime to be the lawyer for a crook.

Why don't crooks do this today? Well, there are two answers. For big crimes, stuff like crooked property deals, they absolutely do this already, it's completely routine. For a phishing site they don't bother because it's not necessary. If 90% of visitors to your unsecured http://paypal-credit-checking.example/ fill out the form, and you get that up to 99% by obtaining a DV certificate for it, why spend $500 setting up a US corporation for the extra one percent? But if you persuade everybody EV is great, then sure, that's what they'll do next.

Re: The Power to Revoke Lies with the Certificate Authority

#52
post #35

Earlier quoted context omitted.

>they went straight to the CAs, and the CAs folded on an arbitrary rather than legal decision, which is a little concerning, but also not too concerning. the CAs were probably were just alerted to the fact that ian was running a website in an obvious bid to confuse people, and decided to revoke his cert. and honestly I think that's a fine, reasonable response to what ian did -- Bullshit. It is utterly insane to accus…

> It is utterly insane to accuse him of running this page in an "obvious bid to confuse people" [...] And what about this? https://stripe.ian.sh/firefox.png

That's called using developer tools to create a mockup of a page.

Re: The Power to Revoke Lies with the Certificate Authority

#53
post #35
post #5

Earlier quoted context omitted.

right. and he passed the checks because his perfectly legitimate company is also called stripe inc and is also in the US, just in a different state. now stripe could take this up with the courts about how ian is confusing consumers and so forth, and they would win. but they didn't - they went straight to the CAs, and the CAs folded on an arbitrary rather than legal decision, which is a little concerning, but also not…

>they went straight to the CAs, and the CAs folded on an arbitrary rather than legal decision, which is a little concerning, but also not too concerning. the CAs were probably were just alerted to the fact that ian was running a website in an obvious bid to confuse people, and decided to revoke his cert. and honestly I think that's a fine, reasonable response to what ian did -- Bullshit. It is utterly insane to accus…

> Bullshit.

no, not bullshit. see the screenshots in this thread and the tweet in the post itself where the two stripe sites are compared side by side. making a "look how useless EV SSL is" site through a phishing example isn't a good strategy for maintaining an EV SSL cert, clearly. he was practically asking them to revoke it, and they gave him what he wanted.

> (My site sells legally scraped public data from that BigCo's website, instead of suing me they prefer to just keep my site offline)

it sounds reasonable that cloudflare kicked you off, too. you may not be breaking the law, but you're not respecting BigCo's terms of service and you can't expect a red carpet given the nature of the business you're in. seems like an interesting/fun game of cat and mouse, in any case :)

I'd be much more worried about this kind of thing if it were happening to good/neutral actors. but as presented it just seems like the centralized internet doing a pretty OK job of policing itself.

Re: The Power to Revoke Lies with the Certificate Authority

#54
post #49

I agree with the fundamental conclusion that, due to changes in the Internet, CAs are quickly becoming arbiters of what content is valid or not in the public's eyes -- a job they aren't ready for and never asked for. The article linked goes about discussing this issue in a hyperbolic manner and it commits a few critical thinking mistakes despite arriving at a valid conclusion. Briefly, I'm going to focus on just one…

Your argument hinges on your word "abuse". Except there's no abuse. Nothing stops Ian from conducting business legally with that company name. If CAs have a problem, they need to fix the cert system. What should those guidelines look like? "You need to have a legal entity, but not one that conflicts with any big brand names people might know, even if you're legally entitled to conduct business under that name"?

There was no forgery.

Re: The Power to Revoke Lies with the Certificate Authority

#55
post #53
post #35

Earlier quoted context omitted.

>they went straight to the CAs, and the CAs folded on an arbitrary rather than legal decision, which is a little concerning, but also not too concerning. the CAs were probably were just alerted to the fact that ian was running a website in an obvious bid to confuse people, and decided to revoke his cert. and honestly I think that's a fine, reasonable response to what ian did -- Bullshit. It is utterly insane to accus…

> Bullshit. no, not bullshit. see the screenshots in this thread and the tweet in the post itself where the two stripe sites are compared side by side. making a "look how useless EV SSL is" site through a phishing example isn't a good strategy for maintaining an EV SSL cert, clearly. he was practically asking them to revoke it, and they gave him what he wanted. > (My site sells legally scraped public data from that B…

>the screenshots in this thread and the tweet in the post itself where the two stripe sites are compared side by side

It's not at all clear whether or not the page was ever publicly accessible like that. It certainly doesn't appear that he was distributing the link to the page if/when it looked like that.

https://web.archive.org/web/20171211181630/https://stripe.ia...

https://crt.sh/?id=393002115&opt=ocsp

The site looked like this for at least 4 months until the cert was revoked.

"obvious bid to confuse people" was a pretty harsh accusation, and you have essentially nothing back it up.

>site through a phishing example

Even if he had copied the stripe page, that still wouldn't make it phishing.

Re: The Power to Revoke Lies with the Certificate Authority

#56
post #19

The idea behind EV's (to tie domain ownership to real-world legal entities) is sound, it's just that the implementation is poor. If the EV badge identifies a legal entity plus its country of origin, then how is it supposed to be the CA's fault that there's this leaky abstraction of multiple legal entities with the same name in the same country? If we have a good idea and a poor implementation, then the correct respon…

But how would that help? Both Stripes would have a valid first class identity with valid keys. How are clients supposed to then check?

In the current system, the client must query the CA that issued the EV cert for the legal entity data. This presents a number of problems:

a) not all CAs will present enough distinguishing data to the client. Case in point: "Stripe Inc. [US]"

b) No consensus between CAs as to who will issue a cert for a given legal entity. In other words, there is such a thing as a CAA record for DNS and DV certs, but no such thing for EV certs and therefore no verification flow of for a given legal entity -> which CA is permitted to issue -> which domains have been certified for that legal entity

c) No support for more complex identity usecases including name changes, subsidiaries, brand licensing (this FedEx-looking site is run by Acme Local Fulfillment Inc. which has been licensed by FedEx to use the FedEx brand), etc.

Certificate Authorities are not in the business of establishing identity and so they are fundamentally doomed to doing a poor job of verifying identity. Instead of trying to coerce CAs into the identity business because of the inflexible and glacial pace at which government moves, we should be pressuring government to adopt more modern identification practices.

Re: The Power to Revoke Lies with the Certificate Authority

#57

Earlier quoted context omitted.

IDN homograph attack should not be an issue in your address bar - unicode letter trickery e.g. pаypal.com with a cyrillic а should be shown as xn--pypal-4ve.com ; it's something that can be solved and is being solved on the UI level.

Oh nice, they've fixed it in every major browser?

Firefox users can visit about:config and manually set the value "network.IDN_show_punycode" to True, to fix this. Tested and working, and I'm not sure why this isn't already the default for users whose language setting is English.

Re: The Power to Revoke Lies with the Certificate Authority

#58

There are several points in this post but the bulk of it is, I feel, one of those classic fallacies that journalists or security hobbyists often engage in: "I found what looks like a flaw in a system but I didn't try to exploit it for real, look how clever I am" So his mate registered a company with the same name as another company and got an EV cert. Well done. Everyone knew that was possible already, at least every…

"If he had been, and had used that EV cert to phish Stripe customers, he'd have been reported to the police using the details from the CA and possibly prosecuted. Bear in mind he had to register a company in the USA, not Kazakhstan." Are you _from_ the USA? Or do you believe its propaganda from outside? You don't need to even be able to point to the USA on a map to set up a US company and do all this paperwork. You f…

>For a phishing site they don't bother because it's not necessary.

It also wouldn't scale, domains get blacklisted within minutes or hours, getting an EV cert takes longer than that.

Re: The Power to Revoke Lies with the Certificate Authority

#59
post #46

Revoking lies sounds like an amazing power.

I was also confused for a moment. The title is an example of a garden path sentence[0]. You get several word into the sentence parsing it one way before you get to a word that doesn't match your initial parsing, so you have to go back to the beginning again and reparse it.

[0]: https://en.wikipedia.org/wiki/Garden_path_sentence

Re: The Power to Revoke Lies with the Certificate Authority

#60

I'm not sure how EV certs have continued to be a thing for so long. Does anybody trust an EV cert more than a DV cert? It's hard enough to get the average person to check for the green padlock before they enter their password, how can we hope to convince anybody to check the company details in the certificate?

> I'm not sure how EV certs have continued to be a thing for so long.

EV certs are currently the cash cow of certificate authorities. If you'd take away EV certs it would become apparent that there's no valid business model for CAs any more.

So the whole CA industry kinda depends on keeping the illusion that EV is a valid concept.

Post reply on HN