CNNIC's response to Google
www1.cnnic.cn
www1.cnnic.cn
My gut feel is that "rogue root CAs" need to have the fear of having their entire business shut down if they're caught out acting badly, and that CNNIC is the ideal opportunity for US-centric technology companies to take a stand without treading on too many profitable toes. If Microsoft and Apple joined in solidarity and announce they're taking CNNIC out of trusted roots (and, to a lesser extent, Mozilla), then it will be clear that the threats to CA's business/profit have some teeth.
If they let this slide - it'll pretty much be open season for root trusted MITM certs to anyone with a few kilo or mega bucks to spare. It won't stop state-level actors from doing state-level bad-stuff(tm), but it might at least stop them from selling that ability to random big-corps as well.
(And surely the opportunity to stand up to the Chinese Government with broad internet-community backing, especially in the face of the recent Github DDOS - the timing is about as perfect as it's ever likely to get, right?)
Okay, so the question isn't actually "how we're going to kill it". It's going to die when there's a better alternative. So the question is really, "What can we do to build a strong web-of-trust system while continuing to use the broken one?"
I see no reason we can't make some browser plugins, get some activism going in the tech community, and start building it. Just report back what cert was served to you.
With that being said, there needs to be a selling point other than building a better internet, otherwise no one will use this plugin. I think there is one, though, and that's security. When your browser comes across a cert that differs, alert the user. You might not get grandma to use it, but it's something.
There are issues with this. I want to anonymously report what cert a website serves me, rather than giving anyone curious my entire browsing history. And also poisoning. But the latter is fixed by using this both the existing CA model and the WoT.
So yes, there are some problems. But c'mon, it's 2015, let's fix this already.
Well, you don't need to pay anyone to do encryption. You do need to do pay people to do identity verification. That's a more-than-pedantic difference, even though encryption without identity verification is generally meaningless.
First off, you're already paying someone to have a domain name. I sorta understand the distaste on principle, but I've never really understood, as a practical matter, why paying $10+/year for a domain name is totally fine, but paying $5/year on top of that for SSL isn't. (And yes, the race-to-the-bottom has hit $5, see ssls.com. This isn't even counting StartCom and the future Let's Encrypt.)
Second, and related to that, what you're paying them for is the human element in key continuity. If you ever lose your key, you're going to want to be able to regain a key for the same website that you've already published everywhere, that everyone already has localStorage for, etc. And be careful about saying that you don't care: Crypto.cat (which, at this point, definitely knows what they're doing) managed to lock themselves out from SSL by requesting a hardcoded public-key pin and then losing all the public keys they'd pinned. This isn't really a risk that you think is realistic until disaster strikes, and the last thing you want in the middle of a disaster is to have to rename your website and convince everyone that they should use the new site.
And the process of maintaining infrastructure to re-provision certificates to people costs money. It's possible that it could be funded in different ways (just like, e.g., all of the work that goes into the browsers themselves is funded in ways that don't involve charging website owners or users). But there is a thing there that involves humans, there are advantages to it involving humans, and humans need to be paid.
What's the race to the bottom for wildcard certs though? Looks like $80+/year, which is frankly completely ridiculous seeing as it's exactly the same amount of work for the CA.
The whole thing's a racket, we would honestly be better off using self-signed certs and certificate pinning (perhaps with a global list of cert pins stored in the browser/a server the browser implicitly trusts)
I mean, we have to trust the browser anyway, might as well make it handle all the security
http://arstechnica.com/security/2015/04/new-firefox-version-...
It's just that lots of other browsers are hesitant to follow suit, because OE doesn't protect you from most attacks that the average internet user would expect encryption to protect you from (e.g., you shouldn't type credit card numbers into an OE webpage). And even Firefox treats the site as http, not https, although the physical connection is over TLS on port 443. That's what, in the browsers' eyes, is "acceptable" encryption, which is what translates to the user experience of having to override the browsers' warning.
It's obviously far from 100%, but the web of trust has to start somewhere. Distributed web-of-trust works for individuals, but am I supposed to go see Jeff Beezos in meatspace before going to amazon.com?
The solution is, of course, delegation. But the end result is you end up with exactly the same CA system as today!
The problem here is that the delegation is too broad; we're delegating verifying all websites to all CAs and assume that all CAs are absolutely trustworthy for it to work. That's ridiculous.
Chrome has a sort-of-solution built on top of this with certificate pinning where the organization gets a cert from the CA, and then gives it to chrome and claims "Only this cert is valid for our site" rather than all CA's certs...
Continuing with our example of BoA, this doesn't matter because they have not opted in [0] to that and in any case that won't apply to non-chrome requests.
[0]: https://code.google.com/p/chromium/codesearch#chromium/src/n...
… which scales up about as far as every domain Google owns/cares about, and a few of their friends/partners/sites-that're-politically-or-business-beneficial-to-Google-to-pin.
I suspect in my 20 odd years of working with ssl protected websites, there's maybe 2 or 3 sites I've worked on that hav a hope in hell of getting into Chrome's pin list. If you're outside the US Fortune500 or any other countries Fortune100, how easy is it gonne be to get Google to pin your cert? It's nice if you're Twitter - it's _never_ gonna work for mygreatcatphotos.org.au...
It's useful, and a great thing they're doing, but as you say, it's _very much_ a sort-of-solution. Perhaps more like a very good two or three bandaid solution, directed at the problem of someone with 99% full body covered 3rd degree burns. "Here, I've got your left thumb and your right big toe covered!"
My guess is no one bothers to fill out the form due to lack of knowledge about its existence.
Surely they let in more than just their friends ... though yes, I do recognize this isn't scalable.
But yes, HSTS preloading is totally open, and has been scaling as well as it's been needed.
This is tricky, but I still don't get how decentralisation solves things, because the problem is still the same, except now it's a risk of whatever web-of-trust node you're a part of being compromised instead of a CA.
- The Perspectives project (http://perspectives-project.org/) aimed to deploy a range of servers (called notaries), through which you can ask "What cert do you see for https://google.com ?", and compare the response. The idea was that certificates should be mostly the same wherever you're asking from.
- Convergence (https://en.wikipedia.org/wiki/Convergence_(SSL)) is a fork of the same idea.
The issue with both of them is, of course, privacy leaks, which the latest version of convergence (https://github.com/mk-fg/convergence#changes-from-upstream) solves with a custom onion routing. The other problem I see is that it still (in the current form) requires the user to manually edit the notaries list.
So, it does exist, maybe it's just lacking publicity ?
https://medium.com/@octskyward/why-you-think-the-pki-sucks-b...
I wrote this article for the Bitcoin community but most of the logic stands for the web too.
The amount of work needed should be pretty low, they start with the current certificate tree and they just need to update in case of a certificate incident (they probably get this info fast and the update should be easy to do via software). Probably they could sustain this service via donations.
I salute Google. For all its forgivable flaws, it stands alone among large corporations in protecting free speech. And the nerve to pull out of the largest internet market on the planet. Kudos.
If your trusted source does not have such a policy, drop them.
I fear my comfortable life with iOS/Android/OSX/Windows/mainstram-Linux OSen at my bidding in various devices and niches, would need to change radically to approach that ideal.
There are no google services in china, so it's definitely an easier stand to take for Google than for its competitors doing business there.
When the Chinese government demanded to be able to sniff all traffic, Google fought back, refused to play cozy enough with the government, and gave up its chance at a foothold.
There's a whole wiki article on this mess: https://en.wikipedia.org/wiki/Google_China#Ending_of_self-ce...
As seen in the last few years, Google has a fairly cozy relationship with the US government and intelligence community, so I don't think they're doing this just to "protect free speech". Besides, breaking SSL goes well beyond free speech (e.g. industrial espionage etc).
> breaking SSL goes well beyond free speech (e.g., industrial espionage etc)
So we should thank them for protecting us against that as well?
> So we should thank them for protecting us against [compromising SSL] as well?
I'm just saying they have a much wider interest in keeping SSL reasonably secure than just to "defend free speech".
even if everybody decides to take CNNIC root out of their system, I doubt how much it would influence the CNNIC.
It's too late. TrustWave got a pass when they did the exact same thing. The message has been sent, there are no repercussions for willfully abusing your CA status. Only incompetence will be punished (DigiNotar).
The CA system is broken. We will never find any authority that everyone in the world agrees to trust.
And that, ladies and gentlemen, is exactly what they're doing.
I personally have removed their certificates from my system. This is the responsible move to do if you care about your security or don't want your computers to be used as part of the DDoS like we've seen against GitHub.
This suggests no: http://apple.stackexchange.com/questions/23720/how-do-i-un-t...
Let's not conflate two mostly unrelated things here. Removing this root certificate does nothing to stop this attack against Github.
Only if the site you were visiting was over HTTPS, which it was not in the Github attack. Saying that you should remove this certificate if you don't want to participate in the Github attack or similar attacks is simply not true.
Hope someone finds this useful!
security: SecTrustSettingsRemoveTrustSettings (user): No Trust Settings were found.
security: SecTrustSettingsRemoveTrustSettings (admin): No Trust Settings were found. dpkg-reconfigure ca-certificates
And select/deselect CAs you trust.I'm normally a fan of dpkg-reconfigure, but in this case, paging through 25 screens of 6 certs at a time, without search, is a far worse case than firing up your preferred browser, finding the root you want to revoke, and planting a bang '!' in front of it.
Otherwise, the processes vilda and I describe are identical.
We applaud CNNIC on their proactive steps, and welcome them to reapply once suitable technical and procedural controls are in place....
Does that mean anything?
http://www.cnnic.cn/jczyfw/fwqzs/fwqzsdtgg/201403/t20140312_...
Microsoft is using CNNIC certs for their Windows Azure services in China (, which of course is independent from Azure services in other regions, and is jointly operated with Chinese partners).
If I marked CNNIC CA as untrustworthy, I would be expecting some alert in my Dashboard page, I guess.
CNNIC is a relatively recent addition to most browsers' lists of trusted CAs. Moreover, given the popularity of pirated & never-updated Windows XP in China, it would have been foolish for any serious Chinese business to use an SSL certificate from any vendor other than globally recognized ones like Comodo and Verisign.
also lol: 'high usage numbers are in large part due to the software being very difficult to uninstall. Furthermore, whenever a user attempts to install another browser, a warning pop-up claims that the new browser is unsafe and should not be run'
Basically they had to hand over a list of all issued certificates, Google reviewed them, and CNNIC can't issue any new ones without asking Google to whitelist it.
If you click on the white page icon and go to the "Connection" tab, it'll say "This site is using outdated security settings," which generally (always, in current Chrome versions?) means SHA-1.
She only has one "customer": herself.
Using the OpenSSL binary the cost is free.
She decides which hosts she wants to trust, obtains their certs and signs them.
She believes she can trust her own CA more than any commercial, third party CA.
Perhaps she does what they do.
I imagine for example she knows her banker, her lawyer, etc. and can contact them by phone or meet with them in person.
Maybe she also uses her friends to help her decide who to trust.
She only has to verify a relatively small number of hosts compared to a commercial CA.
For something like that, I have always thought they should be disseminating their cert via some other means besides an untrusted computer network (i.e., the internet). Or at least give customers another option.
Perhaps making their cert available at branches (e.g., printed on business cards), mailing it to customers with an expository cover letter, or even publishing it in a newspaper or some publicly available printed source.
Maybe these printed copies would be OCR-friendly, maybe not. I think two blobs of text can be compared to each other for differences without using a computer, and I can think of a few ways to make that easier. In any event, this does not seem an insurmoutable problem by any stretch of the imagination, at least for me, and in my mind the benefit outweighs the cost.
Not sure about others, but I still get plenty of "official" notifications via postal mail. And with increasing frequency they relate to computer issues.
This makes me wonder why certs "must" to be obtained and verified using (a) an untrusted computer network (the internet) and (b) why we need the aid of untrusted third parties often with obvious conflicts of interest to decide for us who else we can trust.
Are these not the two things that that "SSL" authentication and encryption is designed to protect against?