Blizzard's Battle.net Updater Installs Root Certificate
reddit.com
reddit.com
They have a REST server running locally, and they want to link to it from websites on the internet. So they created the domain localbattle.net which points to 127.0.0.1. But there's a problem, they can't use http traffic (because of mixed content warnings, even though it wouldn't really be insecure), so they have to use https traffic. They can't use a public CA because the CA would throw a fit if they found out keys for certs were being distributed in an application (they could lose trust in major browsers due to something like that). So they generate a non-ca certificate (notice the cert doesn't have basicConstraints: CA=true) during setup, install it in the OS so the browsers trust it, and use it in their local webserver. The key is only available on the computer (and I assume it's stored in a secure manner). The only way they could use this cert to mitm your SSL traffic, or phish/pharm you is to do that same process with a different domain in the subjaltname extension.
I think this is a clever and secure solution to the problem they face. At the end of the day you're already running their code on your computer and have given it admin privileges in the past, so you can't say you don't trust the application, and this doesn't introduce any supply-chain type vulnerabilities that could be exploited down the line (that didn't already exist in the auto-updater, which is a much bigger issue I have with the Blizzard client).
So I guess I'm asking, what am I missing, why is everyone freaking out at Blizzard?
(Also not sure if anti-cheat is a factor here?)
This is very concerning. The implication of this is super super dangerous. If anyone gets hold of the private key (which I sure hope is secure, but I'm not holding my breath), they can snoop on all of your traffic, and steal your password and credit card numbers. Usual Root CAs (Commodo, etc...) are held to very very very high standards in how securly they store their private key because of just how bad it is for it to leak. They are forced to undergo a very thorough audit process before being trusted. But since blizzard is not an official CA, they don't have to undergo the same process, even though a failure would be equally disastrous.
There is no valid reason whatsoever to install a Root CA here. What blizzard is doing is simply wrong, from a technical and ethical perspective. From what I understand, it is used to implement facebook login. There are other, better ways to do this. They could use an embedded browser instead of the default browser. They could use http instead of https (the url should be local anyway, and as such, secure). They could have registered a Custom URI scheme. The alternative, secure solutions are plenty.
Furthermore, Battle.net is failing in other ways. Everyone that has battle.net has a permanent server on localhost:22885. From what I gather, this is what they use to implement the facebook login, but the server is always on, instead of being only enabled when facebook login is actually in use. This is another big can of worm. We've seen previously that such things can lead to Remote Code Execution (basically a very convenient way to spread viruses) because any browser can make connections to it.
Blizzard needs to fix this shit now.
So far what I've done under my Windows 7 machine is to placed the certificate under "Untrusted Certificates" and under properties, turned on "Disable all purposes for this certificate". Are there any other measures that I should take to completely prevent this certificate from causing potential harm?
There may be some merit to the point about running the local permanent HTTPS server but that's unrelated to the certificate.
I tried to expand this comment to include a technical explanation of the issues, but it became quite long. I'll try to simplify and summarize: there are legitimate security concerns about applications that install their own Certificate Authorities (CAs, aka root certificates), especially when the same one is being installed on all computers. A Certificate Authority has the ability to issue certificates for any website, so it has the ability to compromise the user's traffic to any website if mismanaged. Blizzard didn't do that. Blizzard installs a randomly generated, unique-to-the-user certificate (not certificate authority) for Blizzard's own website domain name. This does not present any of the security issues alleged by the Reddit comment.
So there is no root certificate or CA involved -- the title of this HN article is incorrect and the Reddit thread is mistaken. (To caveat again: I have not personally verified this, and am digesting information supplied by other HNers) However, if you don't plan to log in to Battle.net using Facebook, then there's probably no downside to disabling this certificate either.
I'm happy to be proved wrong about this, but my experience tells me "most TLS libraries" is misleading even if technically true.
In fact it appears they did exactly the right thing to get https working correctly in their mixed-mode (localhost + outside world) environment.
Now, if you want you can argue that Blizzard weren't to know this would happen. And that, depending on what else they've done this might be safe anyway, but I wasn't commenting on either of those, only pointing out that SChannel doesn't care about basic constraints on trusted roots.
Our recent update to the Blizzard Battle.net desktop app made sure players could properly use features like logging in to Battle.net via a social network, or joining a Blizzard group via an invite link. To facilitate these features, we updated the local webserver to use a self-signed certificate to be consistent with current industry security standards.
For those interested in more detail, using these features requires your web browser to communicate with the Blizzard Battle.net desktop app. Previously, the desktop app used a certificate signed by a public Certificate Authority, meaning that no modifications to your system certificates were necessary; however, this technique is incompatible with Certificate Authority policies and we can no longer use it.
While some browsers such as Chrome and Firefox are equipped to handle browser-to-app communication techniques, the changes were necessary for other browsers. For the time being, the desktop app generates a self-signed certificate that’s unique to your machine and configures your system to trust it.
I don't understand why Battle.net would do this, but I guess NOW they have to issue a statement about this.
Innocent version: oops we made a mistake.
Actual version: oops we got caught with our hand in the cookie-jar.
Arent' they making lots of money off these poor addicts already?
I'm sure with Overwatch trying to become legit and the hundreds of millions that will go towards the Overwatch League, they need to ensure a level playing field.
So HTTPS is just adding entropy through waste heat, it achieves nothing, whatever a client is sending or receiving is trivially intercepted after the decryption.
Anti-cheat in the game client is all about hiding. WoW had this big thing with their Warden system where they downloaded code from the game server, loaded it into the client at runtime and then had some encrypted communication channel back. It was an utterly pointless waste of time because it was so obvious to anyone looking for an anti-cheat mechanism and trivially defeated. What worked for them in the end was doing an "unintentional" out of bounds/uninitialized memory read when assembling a network packet. It looks completely innocuous looking at it in a disassembler (and you wouldn't notice when it's one of 10000 changes in a big patch) but it just happened to send back some bytes of memory that were patched in a cheating client. By now you would probably skip the in-client cheat detection altogether and just do ML classification on movement/interaction/time data at the server.
For example, when a player makes an in-game screenshot [in WoW], this contains a watermark with the account number of that player. So if someone posts a screenshot how they cleverly exploited in the game, and remove their character name, Blizzard can still easily find out their PII because they have the info linked to the account number which is hidden in the screenshot. And its even hidden in partial screenshots.
While the entire “gamer” demographic is now considerably older than it was 10-15 years ago on average I don’t think that WoW has an exceptional demographic in this regard.
If anecdotal evidence to be used than I would say that WoW probably skews younger now despite being a subscription MMO which tended to attract more adults than teens.
Not many 30+ year olds have time for MMOs anymore but we can still log into a CoD or BF multiplayer match over the weekend.
Innocent version: we did nothing wrong and you are reacting before having even looked at that certificate.
[1]: https://groups.google.com/forum/#!topic/mozilla.dev.security...
Edit: This was written assuming CA bit = 1.
So with connections to http://localhost not possible due to mixed content and connections to https://localhost not possible because your cert will be blocked, there doesn't seem to be any obvious way left to connect from https to localhost at all.
[1] https://security.stackexchange.com/questions/104801/why-aren...
localhost and 127.0.0.1 never get exceptions to security rules, including mixed content.
The rational is that there are many intranet and local applications that might be accessible on 127.0.0.1, they were not designed or secured to be accessible from the internet.
Additionally, localhost services are treated as a separate origin, so if a service is non-cooperating, you can only send fire-and-forget GETs which reduces the attack surface considerably.
Ok, so apparently there is a security exception: "localhost" is blocked but "127.0.0.1" is treated as a secure origin [1] - but only if you cantact it via http, not via websocket. (though they might allow websocket in the future too) [2]
(A related chrome bug even specifically mentions the "people installing local root certs" workaround as a reason they are doing this. [3])
This still seems like an enormous mess but it's good to see the use-case is acknowledged and someone at Mozilla cares about it.
So I guess Blizzard could have avoided the whole scare if they had just used "127.0.0.1" instead of "localbattle.net"
[1] https://bugzilla.mozilla.org/show_bug.cgi?id=903966
[2] https://bugzilla.mozilla.org/show_bug.cgi?id=1376309
[3] https://chromium.googlesource.com/chromium/src.git/+/130ee68...
No, not across all applications on your computer. This is not about using your own CA, it's about making other software use your CA. They could just issue an update to their software to trust their own certs instead of infecting the rest of the OS.
edit: to answer my own dumb question, the major issue is that Blizzard or someone who steals Blizzard's root CA private key would be able to impersonate any domain they wanted, instead of just Blizzard's.
Having a CA means they can mismanage any domain.
It means that employees of Blizzard (hopefully not many of them but who knows) can now create certificates that will be accepted as "Wells Fargo" when the user tries to go to "https://wellsfargo.com". Their browser will show the green icon because the browser relies on the Root CAs in the trust store. I think/hope this will break for HSTS sites like most banks. I also think this was likely not intended maliciously by Blizzard. But it's incompetent and opens up unnecessary risk.
The thumbprint is e8e6a2932ae8de6eb3b555270b55fdc72b7db7b7, but it's limited to the subject alternative name "DNS Name=localbattle.net".
-----BEGIN CERTIFICATE-----
MIID1jCCAr6gAwIBAgIDAKCkMA0GCSqGSIb3DQEBCwUAMIGSMQswCQYDVQQGEwJV
UzETMBEGA1UECAwKQ2FsaWZvcm5pYTEPMA0GA1UEBwwGSXJ2aW5lMR8wHQYDVQQK
DBZCbGl6emFyZCBFbnRlcnRhaW5tZW50MRMwEQYDVQQLDApCYXR0bGUubmV0MScw
JQYDVQQDDB5CbGl6emFyZCBCYXR0bGUubmV0IExvY2FsIENlcnQwHhcNMTcxMjIx
MjEzNDAxWhcNMjcxMjE5MjEzNDAxWjCBkjELMAkGA1UEBhMCVVMxEzARBgNVBAgM
CkNhbGlmb3JuaWExDzANBgNVBAcMBklydmluZTEfMB0GA1UECgwWQmxpenphcmQg
RW50ZXJ0YWlubWVudDETMBEGA1UECwwKQmF0dGxlLm5ldDEnMCUGA1UEAwweQmxp
enphcmQgQmF0dGxlLm5ldCBMb2NhbCBDZXJ0MIIBIjANBgkqhkiG9w0BAQEFAAOC
AQ8AMIIBCgKCAQEAv4ih+a9V+dd+l97hTyWYLg+b1aj6UrgREMvLv0PFoE63eozs
oFAvjr/0QVCt8RJg2aIF1OZSfc4c9PWkSktFvKB2vMRbVkSwhZvlpDLdQdgD89q9
XZnWv8KmB1w7R7RUzYhNv5IBfqx77hdpMsdfhMAsVu9UNi7Bowhk2Lyk+NSIMMbY
f6TvgoWLLz6Glw1mGSl8ki2SzaFj6xTNdKo56knZBy9wHQlmjv7GVltwmcVeyARC
3Q4qG/tG7t9CchCNUWHMP1Uxc9t2hZbQIjJRIE+h7Njp7A5nNIO0XXkJpKdtank/
Q2+CJNdoX7kNi7frB3y+TVSNYTNxh6bfDyueEwIDAQABozMwMTATBgNVHSUEDDAK
BggrBgEFBQcDATAaBgNVHREEEzARgg9sb2NhbGJhdHRsZS5uZXQwDQYJKoZIhvcN
AQELBQADggEBABFtIjAcF6vgXBWUACc+nvKwLUUAuIDigK+PpTJZ+eqvJd2gjPG+
i9tfSe3Y0uWeHgNAtV3bwV/pEp8jPj0KyS7aYM2QhS2Gezy2NN7RjXtU+tFItwQ3
ykHQsqG5F+KqpDFZrbmuPkXUB9TihxG9aGATBOzhw18RV7hlf/y+60LDMF+8BoYY
AVJ6wDUcYsuO4PQ2DE3DlJJokUsITUlzWYn60Kmo96NG0MST/Zg3bLLC3gxclZb/
vkK/pVha6I8kRyPFkfwIS/4Z/HCwHX9RAxbBaOxGqaN3XgcsR9hGBZD6DRA6iF1u
XfkZ9zz/NfgVIx+AJmyw32X1T5HRcmMhZZ4=
-----END CERTIFICATE----- Certificate:
Data:
Version: 3 (0x2)
Serial Number: 41124 (0xa0a4)
Signature Algorithm: sha256WithRSAEncryption
Issuer: C = US, ST = California, L = Irvine, O = Blizzard Entertainment, OU = Battle.net, CN = Blizzard Battle.net Local Cert
Validity
Not Before: Dec 21 21:34:01 2017 GMT
Not After : Dec 19 21:34:01 2027 GMT
Subject: C = US, ST = California, L = Irvine, O = Blizzard Entertainment, OU = Battle.net, CN = Blizzard Battle.net Local Cert
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
Public-Key: (2048 bit)
Modulus:
<boring>
Exponent: 65537 (0x10001)
X509v3 extensions:
X509v3 Extended Key Usage:
TLS Web Server Authentication
X509v3 Subject Alternative Name:
DNS:localbattle.net
Signature Algorithm: sha256WithRSAEncryption
<boring>Initially this was troubling news though, and will continue to be without some kind of confirmation.
Of course, in practice, I don't think any average bad guy is going to spend the time to write Windows malware that installs Linux malware on other drives or partitions. Just like any security practice, it's a matter of tradeoffs. Is it worth the trouble to disconnect the Linux drive every time you want to play a game in Windows?
So, theoretically, any malware with root-equivalent privileges can do whatever it wants to anything on the system. Also, theoretically, malware can be remotely installed on your WAN-exposed router, infiltrate your network, and install malware using zero-days on every machine on your network. Is it worth the risk to air-gap your machines?
More practically, non-gaming stuff doesn't require a high-end machine, and average/SFF machines are plenty powerful, so it's probably reasonable to have a separate machine for gaming. Just get a KVM switch and put a Mac Mini-type machine next to it for your non-gaming machine. Then do all your gaming, using whatever awful incarnation of Windows is currently required, on the other machine, and never do any banking/email/etc. on the Windows machine, never type any passwords into it (except for gaming-related, of course). Treat the Windows installation as a throwaway, ready to be nuked and reinstalled at any time.
You could look at the "Not Valid Before" date, which is 2017-12-21.
> I got a strange prompt that Agent wanted to make changes on my computer and needed my admin password
An admin/mod should change the title here, but the concern is still the same.
That was rhetorical. It's obvious from the state of modern desktop OSs what the answer is.
Sarcasm aside, I'm a software engineer with a very superficial understanding of the certificate system. I'm not even convinced of my own ability to notice when something's wrong.
Because that's what you're doing when you say shit like this. Thinking like that is what gave us forced automatic updates.
The text of one of your post's siblings is:
> A root lets you make a valid cert for any domain. It can be used to create a man-in-the-middle attack if paired with a proxy.
If you were to walk down the street tomorrow and ask 10 people to define "cert", "domain", "MITM", and "proxy" I'd wager you'd get 0 correct responses. I'd also wager those 10 people use computers every day -- and I don't think that's a problem. You shouldn't have to study and understand byzantine systems just to use a computer.
Could the message explain the problem better? Maybe, but when you characterize the user the way the parent did, you're not going to stop there, you're going to make them jump through all sorts of hoops or just outright deny the ability all together in the name of saving them from themselves, and that's a huge pain in the ass for the people who do know what's going on and are just trying to get some shit done and use their computer as the tool it was meant to be.
[1]Even if the user knew what it was saying it seems unlikely that they'd think it was malicious. They trust blizzard enough to install their software anyway, so if blizzard says they need this thing, why wouldn't they say ok?
Or are you trying to derail the conversation on purpose?
Attention: You must click OK to play this game.
The battle update this week requested to run with admin rights, like a million of setup software. It didn't ask specifically "Allow setup.exe to install a system CA? Yes/No".