How to Detect Sneaky N.S.A. ‘Quantum Insert’ Attacks
wired.com
wired.com
This attack, while impressive and nifty, would seem to be easily subverted by SSL right?* Yet another example that shows that non-SSL HTTP should be phased out.
* In the ideal situation where users check URL's and the CA system is good enough to keep the NSA out.
Broadly speaking, we should. And that's why there's been a lot of work lately in doing things that either build on or bypass the CA system. For instance, even if you get a valid CA certificate for a site you want to spoof, it still has to be a different certificate, so there's more work on certificate pinning. Sure, that doesn't help if the spoof cert is up the first time a given person visits a site, but it still raises the bar for successfully attacking a site surreptitiously, because anyone who hits the site post-pin will get a big warning, which can be picked up with other things. Now the attack has to be even better targeted.
And there's other work going on lately, and while it may not be immediately visible to the general public because this all takes time, it really seems to me this has all gotten a lot more vigorous over the last year. I don't even think it's all Snowden per se... it seems to me generalized security consciousness has gone up lately, like we passed a critical threshold of people's work feeding back on other people's work and the community as a whole has moved to a new level of effectiveness. It'll still be a while before we really see the changes but I think some changes are coming. (Not Utopia. We've still got a long ways to go. But some general improvements.)
I think in general https would work against this particular attack, if you don't accept sites with mixed content (I am not aware of any browser plugin which does suppress plain content on mixed sites).
As a matter of observation, it is kind of amazing how short of a memory even the internet has. It seem to be a knowledge management issue, i.e., new and evolving information is not contextualized or even related to pertinent past information.
Creative use of advertising platforms is used you could easily narrow targets down and guarantee that you know exactly what the content is.
Anyways, this is just one gadget.
A single request going through a bogus certificate emitted by NSA "acquired" CA would be hardly detected.
Or, given the fact that they could indeed broke keys, they could simply do a man-in-the-middle, instead of a man-in-the-side.
There are browser extensions that detect bogus certificates; there's a good risk of catching them.
Sometimes they keep this box offline, but they need to keep a sub-CA online somewhere, or they wouldn't be able to issue certificates.
So, a CA private key and public certificate can be compromised in much the same way a single server certificate.
With a CA private key and public certificate, one can easily emit a bogus certificate for *.google.com or any other domain name. If this CA public certificate is trusted by the browser, a user would hardly notice.
Only incredible ignorance and lack of perspective could permit this.
Its just criminal activity excused by puerile worldviews shaped by propaganda and elitist 18th century philosophies propagated by powerful thugs.
So most people just don't fully (or even partially) grasp the government's surveillance power right now. The media doesn't help here. The media is supposed to inform people about this, but instead either it doesn't talk too much about it, or if it does, the mainstream media is usually pro-mass surveillance (because the powerful friends of the networks are).
Most of the time the lazy reprints of an AP/Reuters story.would dominate, as expected. Once and a while - usually after a really import release such as COTRAVELER[1] - the story would happen... and then suddenly everybody is talking about Prism and explaining how it is "just metadata". Any momentum the new story had ended was redirected into topics that were already known. There would be small-time media doing proper reporting, of course, but it was clear who the "big media" worked for.
The media following the orders of those that sign their paychecks isn't really news, but it was very interesting to watch it happen in realtime.
[1] I still believe that COTRAVELER is one of the most important thing we have learned from Snowden, as it builds relationship maps and it doesn't rely on the target performing some specific action such as an HTTP requests that QUANTUM can race. Bonus: it only relies on "metadata".
America spies because it wants information it can't otherwise have. What are Russia's plans in Ukraine? Is Pakistan playing both sides re: Taliban? Can China shoot down a B2 bomber? We want to know and nobody and asking won't help.
Why we allow them to be better at their art is obvious.
tl;dr Watch for the site to appear to respond twice with the same sequence number. One of those is the NSA trying to get in ahead of the real site.
https://www.usenix.org/legacy/publications/library/proceedin...
And the Github account with the tools to do this yourself, PCAP and rules for snort, bro and suricata: https://github.com/fox-it/quantuminsert
Oh my browser deals with TCP packets??
It's actually impossible to detect these kinds of
attacks. Please go about your business.It's more likely that it would be detected based on the nature of the injected malicious data.
But instead, it's just some dumb TCP man-in-the-middle spoofing, only a bit more sophisticated than Comcast's RST attacks.
[1]: http://security.stackexchange.com/questions/1062/why-dont-is...
It actually depends more on whether you use https on your first connection or not. Because even if the server is set up to only accept https and it tries to redirect you at the first opportunity you'll be vulnerable.
Generally a server configured to use https only will still listen on port 80, and send a 302 to redirect you to it's https version. That redirection can be hijacked by QI.