Key compromise and root cert with exposed key in German lawyer software (beA)
groups.google.com
groups.google.com
(obviously, that's not what they did)
Had the same story 3 days ago on the front page for a different software: https://news.ycombinator.com/item?id=15982161
The problem was what they did before: They had a publicly trusted cert for their local webserver.
Why ask users to import the certificate into the root certificate store instead of packaging the self-signed certificate with and specially loading it from the application. That seems easier from the users' perspective and more secure as you aren't touching the global certificate store.
The problem in this case is not the cert in itself, the local webserver needs the private key. It also uses a non-local domain (bealocalhost.de or something akin to that) which resolved to 127.0.0.1. This is another design brainfart - it assumes that no webserver is running locally, the DNS is in no way protected, making it trivial for anyone who controls DNS to reroute that domain and since they have access to the key, MiTM is trivial. :sigh:
The real problem is they embedded and distributed secrets, instead of generating them. It's funny a game company can do security better than a software firm working for a government. It's sad that I'm not surprised.
I'd bet money that people developing this software knew this was a problem, but government regulation required they use an external CA instead of a self-signed cert because "self-signed certs are always less secure", and nobody was empowered to make this issue known or do something better.
PKI is complex, and certificate expiry is a major source of outages.
Ultimately, I have no idea what they are even trying to achieve here. If this is all localhost communication, HTTPS isn't doing anything.
And what is the motivation behind having a domain you need internet for to resolve to point towards localhost to use with a certificate only localhost is meant to have? This is all sorts of effed up.
Why cant they just use a HOSTS file entry? What is the need for DNS?
If there is no need for DNS then why use the public, commercial CA system? That system relies on domainname registration credentials as "authentication".
Not sure I understand the design of this software. What is the purpose of the web server?
The web server is because it's a locally hosted web app. The DNS name is so a certificate authority will issue them a certificate.
md