Live data from Hacker News

A DNS hijacking wave is targeting companies at an almost unprecedented scale

arstechnica.com

81–90 of 104 posts

Re: A DNS hijacking wave is targeting companies at an almost unprecedented scale

#81
post #18
post #6

Earlier quoted context omitted.

It's some kind of alarmism over letsencrypt ... "letsencrypt will give tricky attackers a valid certificate for a domain!!!" (if they get control over the domain) (... certs have almost always been granted based on control of the domain, though historically it mostly MX records ... so attackers could do pretty much the same thing 15 years ago)

I believe this is why letsencrypt certs are only valid for 3 months. Personally, I'd like it monthly.

I was under the impression that it was more to get admins to automate the issuance and have it auto renew than manually issue and forget and let the cert expire.

If I have control of a dns or register control panel I can use any of the other free ssl certs out there for an attack.

Comodo Will give you a valid cert for 90 days as a trial, others will give you 30 days. AWS cert manager (ok iirc I can only use those within AWS but the point still stands. And if I’m being naughty it’s not gonna be hard to acquire a few stolen CC to bill my AWS usage too) will give you a year. All for free. WooSign / StarCom used to issue free 1 year certs (I think wooSign might still do but they are issued by another CA).

Re: A DNS hijacking wave is targeting companies at an almost unprecedented scale

#82
post #73

Earlier quoted context omitted.

No. You just map .com to another key with an agreement that new .com owner pre signs and map existing .com subs the right way . An unaware xxx.com does not need to do anything. As long as its done publically with a bang and enough consensus, disruption should be minimal. Again this is unavoidable in any system that need trust. Thats why I like PoW DNS.

Who is "you"? The people we're afraid of manipulating .COM control the DNS. Google can't "map .com to another key". Their option would be to leave .COM ; that is the gun DNSSEC would give to the USG to hold against Google's head.

You is firefox/chrome/etc. Yes you can. The ownership of .com is not as exclusive/protected as .xxx or xxx.com. Thus the firefox/chrome/etc can map it to anyone they feel. Considering so many high value .com subnames, .com can be transferred to neutral party or even dnsroot. USG do not own ".com" string. No one does. Just like ".".

Re: A DNS hijacking wave is targeting companies at an almost unprecedented scale

#83
post #71

Earlier quoted context omitted.

That article is peddling bullshit. Yes, DNSSEC is not adopted. But what the intention with it is to stop people hijacking DNS requests (re-routing then to rogue servers for instance,) and then returning spurious answers. That’s a relatively simple attack, and it can have fairly serious reprocussions. Just return an A record for the domain and host straight HTTP for example. Or re-divert emails with MX records. Publis…

Here's a story about a DNS hijacking attack unprecedented in scale for which DNSSEC is powerless, and your conclusion is that DNSSEC is an important priority. If you believe control of the DNS is straightforward without DNSSEC, and that control of the DNS is all you need to get an X.509 certificate issued, go get a GOOGLE.COM certificate misissued. Or FACEBOOK.COM. If you actually manage to do it (you won't), turn th…

Thomas' frothing at the mouth is inevitable because this is yet another opportunity for him to insist that DNSSEC is bad, but let's inject some realism.

This is a story about how some unspecified number of sites claim they were "hijacked" over two years but in which all the actual evidence available says they're just idiots whose registrar account password was stolen. "Iran" is mentioned, but to be honest "Script kiddies" is a more rational explanation.

For those new to all this, GOOGLE.COM was picked by Thomas because he reasonably suspects for most Certificate Authorities it's on their "High Risk" list and so they either won't issue or will use a manual verification process. (Let's Encrypt doesn't have a manual process, all High Risk issuances get "Policy forbids" responses). Your domains are unlikely to be so lucky.

But the rest is hyperbole. Sudden dramatic distrust is how the big scene in Rainbows End works, with the Europeans revoking everything under Credit Suisse to try to kill Rabbit. (I love the description of how Rabbit has never conceived of being surprised and so its default expression doesn't leave any room to actually portray the emotion). But in real life nothing so dramatic is possible.

Some time in the first 24 hours the Maxmimum Merge Delay means the certificate becomes visible to people other than your direct victims. That's the first time Google would know. At this point some of my friends at Google might get called. Tactically there are some immediate things they can do, let's assume they choose the most dramatic for Thomas' purposes. Chrome blacklist updates start switching off this one certificate. If you aren't using Chrome (and maybe web browsers aren't even the intended target) this has no effect. If you do use Chrome it make take minutes, or hours, or in some cases weeks to have any impact, the tail for such a change is notoriously long.

Probably in parallel, Google will reach out to the CA's 24-hour contact asking for revocation. If they don't have the private keys (and there's no reason they would) this will be a manual process, and on a good day I'd be astonished if it's done in less than an hour. In theory the CA has no more than 24 hours to revoke. In practice they _routinely_ miss this deadline. It may be days or weeks before the revocation happens depending on exactly what happened and when.

Google would also reach out to the big trust stores. All of them have some capability to blacklist a certificate, none of them can do it quickly and all of them have that "long tail" where it may take months to be completely effective.

Part of that "reaching out" would be raising an "Incident report" bugzilla ticket. Where Thomas imagines a "no notification or further intervention from you" sudden process instead the Incident would get publicly discussed over days and most likely weeks, with everybody keen to understand all the details of what happened and why before recommending any future course of action.

After a few weeks, assuming we decided that somehow the CA was culpable rather than being a victim too, the decision would probably be to impose more audit or other oversight conditions on that CA.

What Thomas conjures up as this Hollywood Action Thriller style sequence of events is actually more like how an aircrash investigation goes. The burning wreckage makes the TV news, idle speculation maybe for a day or two after. But the actual investigation doesn't happen on a TV news cycle, we take our months to piece together all the details, to get a complete story, and then we think about it calmly and we make recommendations. Drama is not what we do.

Re: A DNS hijacking wave is targeting companies at an almost unprecedented scale

#84
post #78

Earlier quoted context omitted.

Criminals who hijack websites do in fact whip up credit cards "like it's nothing". A huge chunk of abuse attempts on websites that process transactions with credit cards is performed simply to bulk-verify stolen cards . Not even to buy things with the cards; just as a sort of scammer mapreduce to see which of their zillion cards work. The idea that credit card forms are a form of defense in depth is lunacy.

Interesting. Could the credit card industry take advantage of this by setting up honeypots - sites that look easily exploitable to the average crook, but that would actually provide card issuers with a list of stolen cards?

They would have to change the honeypots often.

Scammers are fully aware that banks will also use the data to find other stolen cards.

You get reports that 100 people what their details breached. You look though their transactions. The one thing they all used was momandpopsidebusiness.com for small transactions.

These were prob test transactions so now you start looking for other customers whose cards fall under the same pattern and let the other banks know of your findings.

So scammers will use many “test sites” so if one get found it doesn’t it doesn’t knock out their whole batch.

And word would also quickly spread that cctesterrorscammers.com is a honeypot used by the banks and card processors.

You could look at it like they don’t need the honeypots at all as they just need a few customers to report activity on their accounts and then they can start looking at the data they already have on file.

Re: A DNS hijacking wave is targeting companies at an almost unprecedented scale

#85
post #71

Earlier quoted context omitted.

That article is peddling bullshit. Yes, DNSSEC is not adopted. But what the intention with it is to stop people hijacking DNS requests (re-routing then to rogue servers for instance,) and then returning spurious answers. That’s a relatively simple attack, and it can have fairly serious reprocussions. Just return an A record for the domain and host straight HTTP for example. Or re-divert emails with MX records. Publis…

Here's a story about a DNS hijacking attack unprecedented in scale for which DNSSEC is powerless, and your conclusion is that DNSSEC is an important priority. If you believe control of the DNS is straightforward without DNSSEC, and that control of the DNS is all you need to get an X.509 certificate issued, go get a GOOGLE.COM certificate misissued. Or FACEBOOK.COM. If you actually manage to do it (you won't), turn th…

Sure for google.com it’ll fail. But you could do it for many, many others. The reality is that control of a zone is all it really takes for someone to get a cert issued for it. In that context you are most certainly dependent on the accuracy of the DNS.

I didn’t for one minute suggest DNSSEC would help in relation to the attack detailed in the article.

I am just saying that to claim securing the DNS is pointless is, in my opinion, a fallacy.

Re: A DNS hijacking wave is targeting companies at an almost unprecedented scale

#86
post #18

Earlier quoted context omitted.

I believe this is why letsencrypt certs are only valid for 3 months. Personally, I'd like it monthly.

I was under the impression that it was more to get admins to automate the issuance and have it auto renew than manually issue and forget and let the cert expire. If I have control of a dns or register control panel I can use any of the other free ssl certs out there for an attack. Comodo Will give you a valid cert for 90 days as a trial, others will give you 30 days. AWS cert manager (ok iirc I can only use those wit…

This also fixes certificates lasting too long after domains change hands, allows faster deployment of certs with fixes and other new tech. There are many benefits to short expiry.

Re: A DNS hijacking wave is targeting companies at an almost unprecedented scale

#87
post #76

Earlier quoted context omitted.

The CAs, for the most part, only require you prove you control a domain to issue a cert for it. So you’re already trusting the DNS, whether protected with DNSSEC or not, in the existing system.

And yet when attackers want to misissue certs for small sites (for big sites, misissuance is detected automatically and gets CAs killed), they don't exploit vulnerabilities that DNSSEC defends against. Why is that? And given that's the case, why pursue DNSSEC? And how is any of this, any of it all, relevant in a world where registrars can simply speak RDAP to CAs? If you believe the problem is that the Internet will…

Because the DNS as it is allows for the potential to do something similar (by getting a CA to accept fraudulent DNS response, leading them to issue a cert,) without someone seizing control of a domain otherwise.

It makes no sense not to try to secure the DNS.

Re: A DNS hijacking wave is targeting companies at an almost unprecedented scale

#88
post #5
post #3

What ever happened to HPKP? It seems like that would somewhat mitigate these attacks since they rely on using their control over the domain to get a new DV cert. A pinned certificate would at least protect those who have accessed the sites before.

Deprecated/killed. https://www.chromestatus.com/feature/5903385005916160

Is HPKP Report Only also being deprecated?

Re: A DNS hijacking wave is targeting companies at an almost unprecedented scale

#89

Earlier quoted context omitted.

Yeah, but it is a problem with domain-validated certificates in general that kinda defeats the purpose of SSL. It seems most of the time that a web site is "hacked" (defaced) somebody changed the DNS instead of attacking the actual web server. SSL signing can potentially be a second line of defense, but only if having control of the DNS (thus web and email) is insufficient to get a cert.

What are the alternatives? About 20 years ago, I remember having to go through tons of hoops to get a certificate. Faxing corporate docs and other bureaucracy. That can all be forged.

> That can all be forged.

And this is where a lot of the world is heavily behind say Estonia, Latvia (or other countries) that provide cryptographically secure signed documents tied to people, you practically can't forge those documents.

Re: A DNS hijacking wave is targeting companies at an almost unprecedented scale

#90
post #76

Earlier quoted context omitted.

And yet when attackers want to misissue certs for small sites (for big sites, misissuance is detected automatically and gets CAs killed), they don't exploit vulnerabilities that DNSSEC defends against. Why is that? And given that's the case, why pursue DNSSEC? And how is any of this, any of it all, relevant in a world where registrars can simply speak RDAP to CAs? If you believe the problem is that the Internet will…

Because the DNS as it is allows for the potential to do something similar (by getting a CA to accept fraudulent DNS response, leading them to issue a cert,) without someone seizing control of a domain otherwise. It makes no sense not to try to secure the DNS.

Securing the DNS (a) doesn't fix the underlying problem for TLS (as you can see by the last 2 waves of CA-missuance takeover attacks, neither of which relied on wire-level DNS hijacking) and (b) adds nothing to any secure protocol, which already has to do end-to-end verification today. Despite that, DNSSEC is already the most expensive proposal we have on the table today, requiring every major site and every major piece of software to upgrade or reconfigure.

Deploying RDAP and adding it to the CA/B Forum Blessed Methods gives CA's themselves an end-to-end ability to validate domains, decisively solving the DV problem, and doesn't require any of that expense.

Explain to me again why we should choose the former over the latter?

Post reply on HN