South Korea NIS admits to "packet tapping" Gmail
english.hani.co.kr
english.hani.co.kr
The list of things law enforcement can do to capture GMail messages without secretly having compromised the most important encrypted protocol in the world includes:
* Having owned up the target's box and installed malware
* Having owned up the target's box and installed a bogus certificate
* Redirecting the target to a bogus GMail and assuming the target doesn't care about cert warnings
* Posing as a man in the middle and assuming the target doesn't care about cert warnings
and on and on.
Is it outside the realm of possibility that a nation state actor might have figured out a flaw in the SSL/TLS protocol that would allow them to decrypt traffic? No.
Is it outside the realm of possibility that such an actor could have a bogus root certificate, or a bogus Google certificate? No.
Is it outside the realm of possibility that an actor possessing one of those things would then proceed to use that capability in the course of mundane law enforcement activity, on the record, exposed to public court proceedings? Yes. It is unpossible that that happened.
The article also claims that Google uses deep packet inspection to do its targeted advertising. This does not inspire confidence in its accuracy.
The most probable situation here (if it actually occurred) is that South Korea owns a certificate authority that is accepted by browsers and did a MITM attack with their own google cert.
I do think it's highly improbable that they would use that capability for run-of-the-mill law enforcement cases.
But on you second point I agree. If they are prepared to use such capability, it would be really stupid to reveal their will to do such dirty tricks in some ordinary matter - better save it for a real need.
They're not obvious attacker certs, but Ralph Holtz has found some very strange certs in S. Korea with SN:"Government of Korea" and CA:TRUE. http://www.mail-archive.com/cryptography@randombit.net/msg01...
Also, it's not clear that this is "run of the mill law enforcement". This is NIS, the S. Korean state intelligence service, which is admitting to having done this.
"First rule of State-run CA Club is...
I do not doubt for a second that any reasonable national cybersecurity agency has this functionality readily available, utilizing one of the CA certificates bundled with common OSes. Whether they are actually using it and to what extent is another question, which ties into political implications should someone detect the certificate forgery.
If so I would imagine 95+% of users aren't/weren't using HTTPS, making it trivial to read most of the population's Gmail.
Edit: I was wrong about "definitely true about a year ago", they turned HTTPS on by default in January 2010. http://gmailblog.blogspot.com/2010/01/default-https-access-f... . Seems reasonable that the government could only have been "packet tapping" before 2010.
They never responded.
Odds that this was before Gmail instituted HTTPS or that there is some other explanation that the reporter missed: 99.9%
However, importance if the former is the case: World changing news. But extremely unlikely.
most of the time when a browser warns you that a certificate is bad there's nothing wrong
I've never had a false-positive browser warning. I assume you're complaining about Firefox's and Chrome's treatment of self-signed certificates, which is completely appropriate. Self-signed certificates should always be rejected, unless the user has manually added them to the keystore.Still, if protection from completely passive eavesdropping is all you care about, you can use anonymous Diffie-Hellman to negotiate an ephemeral key. The protocol supports it. Heck a lot of home-grown client software doesn't even check the name on the cert and ends up with effectively just that by accident.
Feel free to add your own self-signed exceptions. I find it useful myself.
But that's not what HTTPS is and it's not how web browsers work. By definition, the lock icon in the user's browser means that the server (as displayed in the URL) has been authenticated to the user.
Can you elaborate on this? I'm genuinly curious.
SSL is possible and commonly done correctly. It is not a joke security wise. (If it is a security joke, show me something that isn't a security joke).
Unless you are a government (or have similar resources), you cannot hack SSL.
SSL would work a lot better if it worked more like SSH, where you could check to see if you have the right fingerprint at the beginning. And of course you can use it like this, but your browser tells you horrible things will happen. Alternately, a true web of trust with something more like the notaries might be useful.
But when it comes right down to it, any scheme of communication that relies on a variety of third parties for security isn't going to work, because you never know when one or more trusted parties are the eavesdropper.
Sure, the crypto works fine, but in practice good crypto often just lulls people into a false sense of security. "The browser shows https" is really a pretty weak indicator that no MITM is happening. I especially say this in contrast to something like an SSH handshake, which is a pretty strong indicator that no MITM is happening, especially if you validate your keys.
And the 95% of the population who don't know what a key fingerprint are, the people who are most likely to click on random things online, those people will just blindly accept that from every site on the web and then they can get MitM'ed easily by people in Starbucks. Right now you can't do that with HTTPS.
Firefox's Cert Patrol or Chrome's certificate pinning are really the best defenses against this kind of thing. If you're on Chrome 13 or later, you're mostly guaranteed that gmail.com is the real deal.
(At least according to Reddit's discussion on this event).
Specific comment: http://www.reddit.com/r/netsec/comments/kj25j/south_korea_ad...
To corin_ : perhaps he wanted a link to see the discussion rather than a source.