Live data from Hacker News

A world of hurt after GoDaddy, Apple, and Google misissue 1M certificates

arstechnica.com

71–80 of 143 posts

Re: A world of hurt after GoDaddy, Apple, and Google misissue 1M certificates

#71
post #68
post #60

Earlier quoted context omitted.

> Such an attack doesn't exist. As far as we know. > Any such attack would also become feasible with twice the budget. Assuming that the attack yields to parallel computing and scales linearly with more cpu/cores, because linear programming is bound to current compute capabilities and then theoretical limits like Bremermann's limit and Margolus–Levitin theorem.

Yeah, assuming these true things.

Assuming the parallelism of an algorithm that you know nothing about is beyond foolish.

Re: A world of hurt after GoDaddy, Apple, and Google misissue 1M certificates

#72
post #9

> Adam Caudill, the security researcher who blogged about the mass misissuance last weekend, pointed out that it’s easy to think that a difference of 1 single bit would be largely inconsequential when considering numbers this big. In fact, he said, the difference between 2^63 and 2^64 is more than 9 quintillion. Okay, but, that's because 2^63 itself is more than 9 quintillion. Where the search space was previously 18…

Or, if the safety margin here is really only one bit, we should probably increase the minimum. If 63 is unsafe today, 64 will be unsafe tomorrow.

If you discovered your AES key generator only created 127 bit keys, would you correct the mistake moving forward? Or go back and immediately burn everything with the old key? The difference between 2^127 and 2^128 is much, much more than 9 quintillion.

Re: A world of hurt after GoDaddy, Apple, and Google misissue 1M certificates

#73
post #69
post #66

Earlier quoted context omitted.

And my claim is that if your threat model depends on an attacker who can afford $20M being unable to afford $40M, your threat model is flawed and you've already lost. They might have to seek alternative options. They might not. They might just be able to issue $20M of bonds, who knows. They might have a strong economy next year and the attackerbucks-to-USD exchange rate might double. If you need to defend against an…

> And my claim is that if your threat model depends on an attacker who can afford $20M being unable to afford $40M But is it? I think the underlying claim is that 2X difference doesn't matter, which is patently false.

A 2X difference from baseline does not make a meaningful difference in who can attack you.

Re: A world of hurt after GoDaddy, Apple, and Google misissue 1M certificates

#74
post #69
post #66

Earlier quoted context omitted.

And my claim is that if your threat model depends on an attacker who can afford $20M being unable to afford $40M, your threat model is flawed and you've already lost. They might have to seek alternative options. They might not. They might just be able to issue $20M of bonds, who knows. They might have a strong economy next year and the attackerbucks-to-USD exchange rate might double. If you need to defend against an…

> And my claim is that if your threat model depends on an attacker who can afford $20M being unable to afford $40M But is it? I think the underlying claim is that 2X difference doesn't matter, which is patently false.

2X difference doesn't matter to a reasonably constructed cryptographic threat model. Any threat model for which a 2X difference is meaningful is already flawed. I'm not saying a 2X difference doesn't matter in general. I'm saying a reasonably constructed cryptographic threat model is going to consider attacks as either "worth worrying about" or "not worth worrying about", and any maybes, like the possibility of an attacker who already controls $20M finding another $20M, fall in the "worth worrying about" bucket.

Re: A world of hurt after GoDaddy, Apple, and Google misissue 1M certificates

#75
post #69

Earlier quoted context omitted.

> And my claim is that if your threat model depends on an attacker who can afford $20M being unable to afford $40M But is it? I think the underlying claim is that 2X difference doesn't matter, which is patently false.

A 2X difference from baseline does not make a meaningful difference in who can attack you.

It could make the difference of mounting a hash collision before a certificate expires or after (2X time), if the attack doesn't yield to parallelism and time becomes a limiting factor.

Re: A world of hurt after GoDaddy, Apple, and Google misissue 1M certificates

#76
post #51
post #37

Earlier quoted context omitted.

I think this is a general fallacy held by a lot people. The notion that someone who has access to X amount of funds for a given task automatically has 2X and can also afford to spend 2X on the given task is not necessarily true, so such claims are generally baseless. What is most interesting is that these claims are generally about non-exact amounts, so the logic should follow that if you can afford X, then you can a…

I'm not sure but I think you're trying to say I'm wrong. In the general case it's wrong, of course, to say that being able to afford X implies being able to afford 2X: few people could afford 2x their rent or a house 2x the price of theirs, etc. Few people would fail to be meaningfully affected by getting 2x (or 1/2x) their salary. But I'm talking specifically about cryptographic threat models. No reasonable threat m…

A signed integer with 64 unsigned bits isn't even convenient for computers.

Re: A world of hurt after GoDaddy, Apple, and Google misissue 1M certificates

#77
post #39
post #29

Earlier quoted context omitted.

The basic story as I understand it is that DarkMatter under contract to the United Arab Emirates wants to become a trusted CA, and they are widely expected to start running a governmental MITM once trusted, but the CA root programs don't have any provision for "You're a bunch of sketchy creeps, we don't trust you." (Oddly enough for a "trusted" root program, there is generally no actual evaluation of trust as convent…

It's amazing that we anticipate having to revoke malicious CAs as a crucial part of a security model, yet we have basically no plan to ensure that we don't accept a competent-but-malicious CA into the fold in the first place.

Competency in this case can be objectively reinforced, but maliciousness requires one to device who is “bad” and who is “good” which is not a technical problem.

Re: A world of hurt after GoDaddy, Apple, and Google misissue 1M certificates

#78
post #40
post #10

Sooooo all the big players depend on one CA PKI package: EJBCA - is that not a major concern ?

That seems like the correct state of things. More packages means more possibility of bugs. We want to trust as little code as possible. Now if only the same policy would be applied to CAs (possibly a few to mitigate abuse of power concerns, but far less than are in my trust store today).

Counterpoint (which I'm not fully convinced of myself, to be fair): CAs are supposed to be interchangeable and easy to revoke. While the CA ecosystem as a whole must be robust, no individual CA can be too big to fail. If a serious bug is found in software used by one or a few CAs (imagine something like the Debian OpenSSL bug from 11 years ago), revoking them and requiring customers to move to other CAs is feasible. If a serious bug is found in software used by all CAs, you can't revoke all the certs on the web and leave HTTPS useless globally while CAs set up new software.

On a tangent: one practice I'd genuinely like to see for security reasons (and which I'm surprised the CAs haven't proposed themselves, since it would make them twice as much money) is that major sites should always hold valid certs from two CAs, so that if a CA gets revoked it's just updating a file or even flipping a feature flag and certainly not signing up with a new CA. It would make sense to have two certs generated by different software, then. (It might also make sense, re abuse of power concerns, to present both certs and have browsers verify that a site has two valid certs from two organizationally-unrelated CAs. That way you can be significantly more confident that the certs aren't fraudulent.)

Re: A world of hurt after GoDaddy, Apple, and Google misissue 1M certificates

#79
post #71
post #68

Earlier quoted context omitted.

Yeah, assuming these true things.

Assuming the parallelism of an algorithm that you know nothing about is beyond foolish.

Right, which is why we know things about the algorithm.

Re: A world of hurt after GoDaddy, Apple, and Google misissue 1M certificates

#80
post #3

Given that there seems to be no security impact (and none expected in the next year or two)... Curious why everyone doesn’t agree to use 64 bits in future and just let the mis-issued certs live out their natural life? Seems to create a lot of busywork for lots of people for no discernible benefit?

The reason for the urgent fixes is to promote uniformly applied rules. There are certain predefined rules that CAs need to follow, regardless of whether the individual rules help security or not. The rules say the certs that are badly formed need to be reissued in 5 days.

If these rules are not followed and no penalties are applied, then later on when other CAs make more serious mistakes they'll point to this and say "Apple and Google got to disobey the rules, so we should as well, otherwise it's favoritism to Apple and Google."

Post reply on HN