ETA: of course CAs have their own private keys, but they don't have the private keys of their customers.
ETA: of course CAs have their own private keys, but they don't have the private keys of their customers.
But you're correct that even if the NSA got the CA's private key, they could only "forge" certificates and this would be detected by certificate pinning. (Similar to the Comodo/Digitnotar compromises)
Could they for example present a generic login and then mitm from thereon?
EDIT: Maybe ip traffic would reveal this. But what if they were to target an individual? I'm just trying to get to the bottom of this.
And there's no way they could scale it up to deal with google or facebook. They'd have to put start buying dozens of datacenters around the world and a vast amount of bandwidth. And they'd need to be able to hijack an enormous amount of traffic.
Honestly, it seems like buying up zero-day exploits and putting malware on people's computers would be oh so much easier and much much cheaper.
That's not a safe assumption. Given that this is the NSA we're talking about, it's probably within their capabilities to transparently MITM all connections to your server.
the CA then verifies your identity, and then produces a certificate by signing (using their private key) the message digest of the concatenation of:
- certificate information: server name/organisation/country/... (the "subject"), start date, end date, etc
- your public key
- the subject of their certificate
your private key should never leave your system.
the NSA could then can use that to MITM sites without explicit pinning.
So when you look at the chain you see:
Verisign (lol j/k really the NSA) -> Site cert
Rather than:
Verisign -> Third party CA (suspicious) -> Site cert
If you pinned the site certs you should be able to defeat both of these.
Coercion by legal means, moles or good old hacking or planting bugged hardware in the targets system and extracting private keys. Its within the realms of NSA, remember, they have the capability to make their own processors.