An update on attempted man-in-the-middle attacks
googleonlinesecurity.blogspot.com
googleonlinesecurity.blogspot.com
Sign a Google Mail certificate for Iran? Fuck you. You're done.
In the medium term, I think a lot of HN people should also take a hard look at CONVERGENCE.IO. For now, though, it's heartening to see the real power behind Internet trust (hint: it's not Verisign and it's not the IETF) taking this seriously.
This is the third time this year that a Comodo reseller has been breached. Comodo should scrutinize their customers better or THEY should get blacklisted (taking all their other resellers with them) at least until they made sure that their clients have all resolved their security issues
It kind of highlights the difficult problem of when to decide to blacklist a CA in the current model.
And for clarity, who/what do you think is the real power behind Internet trust? I've been thinking about it for five minutes and can't come up with a good answer.
Nobody, it's all fiat. Verisign started this scam and we're just seeing the follow-on effects. There has never been anything more than the words and policies supporting the CA industry.
If they were hacked into, spoofed into giving out a certificate, or raided by special forces and had data physically stolen from their servers, then perhaps they can generate a new key and have that become trusted once they've taken steps to ensure something like this doesn't happen again.
But there's no way anyone can trust their old root key anymore.
Nice website, no idea if it works. Sounds cool, but more Beta than a Google Beta I guess.
I love the fact that Google can push changes out to Chrome users immediately. That's a massive win for everyone.
But, you said "medium term." What's the long term?
http://www.vasco.com/company/press_room/news_archive/2011/ne...
Just incredible: They were hacked and they knew it, then forgot to clean up a certificate the hackers generated.
On July 19th 2011, DigiNotar detected an intrusion into
its Certificate Authority (CA) infrastructure, which
resulted in the fraudulent issuance of public key
certificate requests for a number of domains, including
Google.com.
Once it detected the intrusion, DigiNotar has acted in
accordance with all relevant rules and procedures.
At that time, an external security audit concluded that
all fraudulently issued certificates were revoked.
Recently, it was discovered that at least one fraudulent
certificate had not been revoked at the time. After
being notified by Dutch government organization Govcert,
DigiNotar took immediate action and revoked the
fraudulent certificate.
The attack was targeted solely at DigiNotar's Certificate
Authority infrastructure for issuing SSL and EVSSL
certificates. No other certificate types were issued or
compromised. DigiNotar stresses the fact that the vast
majority of its business, including his Dutch government
business (PKIOverheid) was completely unaffected by the
attack.
Maybe directly, certainly not indirectly.But nowhere do they appear to include a list of these domains...
You're building a new startup in (whatever) Bulgaria. Funds are low, but you want to protect your users by using TLS/SSL. That's easy today, but your 'Think of the good old days' line is kind of killing that option. I know that in my early 'put something on the net' days I didn't pay for a certificate because it was just too expensive.
Nevermind that the process you seem to expect doesn't scale internationally and that I seriously dislike the US centric bias anyway (too much power in one country, without the privacy laws I consider basic standard).
Unfortunately chrome seems to be headed in the opposite direction, removing the URL bar.
eg "The identity of this website has been verified by Thawte SGC CA."
Also, they don't need to understand the technical details. If every time they go to their bank it says 'connection to your bank certified by verisign', and then one day it says 'certified by <someone else>', then a cautious person will be suspicious, even if they are completely nontechnical.
For Google, this was easy as they control both their domains and their browser, but for everybody else who isn't maintaining a browser, they'd have to fall back to solutions like STS which, don't work if the first connection a user sees is already man-in-the-middle'd
I changed the settings in Keychain Access hours ago.
Does anyone know what's going on?
Lock with the warning icon is here because "Unable to check whether the certificate has been revoked."
Maybe their intermediate is signed by some other root CA?
It is my understanding that gmail is dwarfed by both Hotmail and Yahoo! Mail.
> In addition in Chromium 13, only a very small subset of CAs have the authority to vouch for Gmail (and the Google Accounts login page). This can protect against recent incidents[1][2] where a CA has its authority abused, and generally protects against the proliferation of signing authority.
[1] http://googleonlinesecurity.blogspot.com/2011/04/improving-s...
[2] http://www.comodo.com/Comodo-Fraud-Incident-2011-03-23.html
1) it doesn't happen more often
2) that anyone noticed
Its clearly early days. If they had impersonated a download server, they could have got users to download a spiked copy of the browser itself
You'd think that an entity which, say, scrapes a large portion of the Web on a regular basis ... might be able to detect such things.
Meanwhile, there's CertWatch http://certwatch.simos.info/ and The Convergence Project http://convergence.io/
The only problem is that this would kill user experience for 99% of the users who don't care about security in the first place. Thus, browsers need to do some clever UI tricks (e.g. color the thingy in url bar in a different color, etc.) to indicate potential problem to the user yet make it less intrusive.
The bottom line is that the fault is not on the SSL/x509. This infrastructure is not perfect but there is nothing better even in the design. The fault is on the browser developers who are not trying to protect users.
Should/would google display this blog link on top of every google service to alert users in Iran, regardless of browser?
My thought is this blog may not even reach out to majority of users, till they get affected by it unless it is 'broadcasted'.
If you cannot delete it, you can edit the trust settings to never trust it.
Assert it has been removed by navigating to https://www.diginotar.nl/
What's to keep an OS upgrade from restoring the certificate?
A system or user-maintained blacklist seems like a more tenable solution. You don't want to delete the cert, you want to hang a scarlet letter on it. Oh, and not trust it for anything (or better, use it to blacklist any site that attempts to use it).
Or is it supposed to remove the trust only but keep the entry?
Sanity testing by loading the homepage over HTTPS results in a certificate warning on all browsers (Firefox redirected to HTTP).
Someone high-profile in Iran is probably going to get screwed as a result.
I don't know how the CA in question works, but for many CAs it's sufficient to be able to receive mails at the postmaster address of the domain in order to receive a certificate.
So basically you only need to find a single CA that uses this techniques and which uses a DNS server vulnerable to cache poisoning. Probing all of the CAs may be a little bit of an effort, but it's something even a single individual could manage. I would not find it suprising if this was the technique applied in that case.
Or they issued the *.google.com certificate by accident, but if you accidentally issue a certificate as a CA, you can't be trusted by a browser either.
IMHO, this was entirely justified.