Public DNS in Taiwan the Latest Victim of BGP Hijack
blog.apnic.net
blog.apnic.net
"Does CT prevent certificate mis-issuance?"
"No."
"So certs were mis-issued, your bank got hacked, and all your money is gone?"
"Yes."
"So are you going to fix internet infrastructure to prevent cert mis-issuance in the future?"
"Why would we do that? We've got logs, we can see it happen."
"But banks will get hacked again!"
"I don't see your point."One would think there would be a little more trust and transparency. But I guess you only need to buy 1k ips and you are in the same league
The client won't be able to resolve anything, but it can't be used to send the client to other places, turning it into a denial of service
Kind of. The Internet is similar to a chain link fence. Every link in the chain needs to perform its role as expected, otherwise shit breaks.
In the case of the Internet, there are many ISPs that are leak links in the chain.
If you then want to use the IP address to connect to a web server, then you can use TLS. Which, in the case of letsencrypt, again depends on DNS to prevent issuing a certificate to the wrong party.
So if you start with securing DNS, then you can bootstrap from that into securing higher level protocols.
At the moment there is no practical technique to prevent route hijacks using BGP. So it is best to consider that insecure.
As an example, you can forbid Let's Encrypt outright, if you so choose. CAs can also define more nuanced policies, so when they define one you could instead require Let's Encrypt but only with DNS (and thus DNSSEC verification). Because the Ten Blessed Methods have associated OIDs the CAs could (but so far as I know haven't plans to) have a way to say I'm OK with anybody issuing so long as they used a method with DNSSEC checks.
Now, as Thomas Ptacek points out previously, banks like many other security critical organisations have lousy security and so none of this will get done, but that's because they're bad at what they do, as is illustrated by them causing a global financial crisis. They're bad at real world security too, plus ca change.
And if you scroll down the page you will see that validation rates are significantly higher in some countries in Asia.
You would need to actually validate certificates for your chosen DNS over HTTPS server cover the IP addresses you've connected with.
And, you would need to be sure that none of the CAs in your root store (or any certificate they've signed with CA privileges) will issue a certificate that covers that IP while the IP is BGP hijacked.
Unfortunately, if the IP is successfully hijacked, at least to a point near to where the CA does it's observation, it seems likely that the hijacker would be able to successfully demonstrate control over the IP.
> 3.2.2.5.1. Agreed-Upon Change to Website Confirming the Applicant's control over the requested IP Address by confirming the presence of a Request Token or Random Value contained in the content of a file or webpage in the form of a meta tag under the "/.well-known/pki-validation" directory, or another path registered with IANA for the purpose of validating control of IP Addresses, on the IP Address that is accessible by the CA via HTTP/HTTPS over an Authorized Port. The Request Token or Random Value MUST NOT appear in the request.