Fingerprinting Firefox users with cached intermediate CA certificates
shiftordie.de
shiftordie.de
The right fix would be to either always fail a site load that doesn't serve the right intermediate certificate, or do what Chrome and IE do and always find and load the intermediate certificate.
From https://bugzilla.mozilla.org/show_bug.cgi?id=1334485#c11 :
Another approach to this problem is to do AIA chasing (that is, fetch the URI in each certificate to attempt to find an issuer). Firefox currently does not do this for performance and privacy reasons. Doing each fetch is slow (you would probably want a cache anyway, and so would still be vulnerable to this attack). Also, a CA (or even an untrusted party, since you can't verify the trustworthiness of the AIA field until after you've already fetched data from it) can use this to track users.
Someone looking to make such a change would need some data on whether any such cases exist on prominent sites.
"Safari - Especially scary - since the HSTS information is actually persisted to your iCloud account and is therefore retained across devices."
Tor Browser's current defense against cached certificate-based tracking is to set "security.nocertdb" to true
As long as TLS certificates sign domain names you trust that delegation, so having an alternate trust root is stupid (and having 391 of them is beyond stupid).
Firstly, given how many domain registries and registrars there are, there still would be a ton of trust roots (probably way more than 391). Secondly, this would significantly increase the difficulty of managing a domain registrar, and would probably lead to decreased competition in the space (more expensive domains?). And thirdly, the client would still need to manage trusted certificates locally, so client-side complexity is unchanged.
Most importantly, the benefits of a new system must vastly outweigh the cost of migrating to it.
As long as domains are what you generate certificates for you might as well assert that delegation in a cryptographically secure way. It may also be a good basis to make domain transfers more secure.
So the question should be why trust DNS and CA when the DNS is sufficient? And it doesn't have to be DNS, you could use domain names for other things too, but DNS is what end users care about so that's where you need to start.
Another approach to this problem is to do AIA chasing (that is, fetch the URI in each certificate to attempt to find an issuer). Firefox currently does not do this for performance and privacy reasons. Doing each fetch is slow (you would probably want a cache anyway, and so would still be vulnerable to this attack). Also, a CA (or even an untrusted party, since you can't verify the trustworthiness of the AIA field until after you've already fetched data from it) can use this to track users.