Certified Malice
textslashplain.com
textslashplain.com
openssl x509 -in domain-validated-example.com.crt -noout -text | grep Subject
OU=Domain Control Validated
CN=example.com
DNS:example.com
As opposed to EV which does. Authentication is to a legal entity, you have a encrypted channel to that legal entity: openssl x509 -in extended-validated-example.com.crt -noout -text | grep Subject:
jurisdictionOfIncorporationCountryName=GB
businessCategory=Private Organization
serialNumber=09378892
C=GB
ST=City of London
L=London
O=example Limited
CN=example.com
DNS:example.com -
(Domains are also required to be reviewed by a human for EV)Disclaimer: work for CertSimple, who only does EV certificates (which match a cert to a legal entity). Though I use DV for my personal site.
Edit: You also cannot just discard certificates and use HTTPS as an "I'm talking to the same server I was 5 seconds ago", because that does literally nothing to prevent MitM attacks. If you can't assert that you're talking securely to the domain owner, then there's nothing at all stopping someone in a privileged network position from intercepting and altering your traffic, because they could simply proxy it through their own server.
>does literally nothing to prevent MitM attacks
It does more than nothing. Especially if you make the reasonable assumptions that 1) the user is not being MitMed most of the time and 2) the user is likely to have connected to the (small) set of sensitive sites before they experience their first MitM.
Example: my home internet is unadulterated. I check my mail. My computer saves the certificate. I go to a coffee shop. I check my mail again. Somone tries to MitM me. My computer instantly spots a changed certificate.
Obviously we should still use and verify certificates. But I notice a nasty trend of making the perfect the enemy of the good in security. There's a perception that if it's not perfect, it's worse than useless and should be shunned (probably due to historical bad experiences with false senses of security).
Not exactly sure what that'd buy...
That's worth something. But as the article points out, it doesn't help if you started out with the wrong domain name. (How do you get the bookmark in the first place?)
EV has the security benefit over DV in that you can use HPKP to pin EV CA public keys, so no DV certificates will ever be trusted for your site.
This statement does not make sense. Could you explain what you are implying here?
Presumably, MitM'ing the CA's traffic to the domain owner is significantly harder than MitM'ing a random user, though certainly not impossible.
HTTPS without certs means you are talking securely to your attacker :-)
This attack also requires the user to ignore the suffix.
I think Chrome used to do this too, but it doesn't for me right now; I'm not sure why.
So, in effect, CAs issuing DV certs for websites, including phishing sites, is a feature, not a bug. If users are misinterpreting what a DV certificate means and doesn't mean, then it is up to browsers to make clear the difference between DV, OV, and EV.
A Domain-Validation certificate is just that. We shouldn't expect it to act like OV or EV.
So while I see your point, that's another transition that will take years to drill into public awareness - even if the browsers could agree on a meaningful and consistent representation, which seems like its own challenge
They've both useful- they've more useful together, and they're expensive and not used everywhere because of the identity problem.
This is just going to have to be accepted (for a while?) to get proper encryption.
Pointing out that this can happen is neither useful or news, and perpetuates this nonsense that's been holding us back.
It's not a stupid desire. Encryption is pretty useless without authentication.
DV certs tie encryption to a purely digital identity while EV ties that identity to a real world identity as well.
The average banker, on the other hand, does care about the identity verification.
Why have we decided that everyone must have the banker's use case?
Of course, the non-internet version of a CA, credit rating agencies, do not behave any better with the trust given to them by the public.
Maybe the creators of the Bitcoin alt coin "namecoin" had the right idea.
As the original article points out, you can perform these kinds of attacks with any address by setting up sub domains ("https://www.paypal.com.safe.com" looks pretty similar to "https://www.paypal.com" to most users).
I personally think this is an issue with the browser UI/UX as it currently stands. "Secure" sends the wrong message to your average user. I would like to see something like the prominent display of the second/third level domain at the top of every browser tab (depending on the TLD). i.e. "ycombinator.com", "paypal.com", etc.
It's very easy: get the browser vendors to remove them from the root store. It's exceedingly effective. The "problem" is that the browser vendors seem to agree that CAs shouldn't be content watchdogs.
Did you read the linked position paper from LetsEncrypt?
So if a CA offers a certificate to a legitimate wordpress site, which then proceeds to let itself get hacked and host a phishing page, that CA now has to pay a fine?
In fact, the browser itself could do this...
2. Have a way for user to easily and prominently display name or domain who is the certificate issued for, hardware button would be best IMO.
No participant in this CA racket has any interest for this to happen...
First time that I am hearing users prefer a vague error explanation than truthful precise one.
And there is a silver bullet. Teach people - and most people already know it, don't assume people are idiots - how to recognize a domain name. Then the padlock. But, domaine names are infinte more important than padlocks. Always been the case and will likely never change in the near future.
You say don't assume people are idiots. I agree, most are not. I will go further and say that, even among those who fall for these scam sites, most are not idiots (though the proportion is higher.)
But! You underestimate the scammers, and you underestimate the size of their toolkit. Sure, it's easy to look at an example like paypal.com.evil.com and think "I can teach users to read that properly". Maybe you can. But how about paypa1.com? And how about once we start playing games with Unicode? Can you tell a Latin lowercase A from the Cyrillic one? Are you going to teach users to copy and paste any suspicious URL into hex editor so as to make sure that its ASCII?
You're right about at least one thing: if you could get people to read domain names, that would be a silver bullet. And it's definitely possible to much better than now. But I worry that the scammers would simply up their game in response.