4 ms·
While I appreciate the intent of the okTurtles folks, I think their reasoning about Google Chrome is flawed. If I, as the user, want to override HPKP, it shoul
by DanielDent 11y ago
While I appreciate the intent of the okTurtles folks, I think their reasoning about Google Chrome is flawed.
If I, as the user, want to override HPKP, it should be easy for me to do so. Perhaps, for instance, I'd like to MITM my own traffic for debugging purposes, or to get an idea of what data an app is transmitting.
Let's imagine for a moment that Google modifies Chrome the way the okTurtles people propose. Nothing stops Dell from writing a kernel patch which detects that code path and alters the functionality at runtime.
If you own the system, you can make it do whatever you want. And Dell starts out owning the system here.
- x0x0 11y agoArticles like this are some of the funniest posts on Old New Thing, eg [1]. There's no alternative to trusting everyone you allowed to install software on your machine or who has admin/root access. [1] http://blogs.msdn.com/b/oldnewthing/archive/2014/07/03/10539205.aspx http://blogs.msdn.com/b/oldnewthing/archive/2014/07/03/10539...
- pdkl95 11y agoYou seriously don't see any difference between 1) Dell installing a cert that applies broadly with plausible deniability (the current situation), and 2) Dell installing a similar cert and explicitly overriding some sort of per-domain debug setting? Yes, Dell could do anything they want, but the latter situation clearly establishes mens rea[1]. https://en.wikipedia.org/wiki/Mens_rea https://en.wikipedia.org/wiki/Mens_rea
- shkkmo 11y agoThe article addresses this explicitly. The point is to reduce the attack surface and limit the damage that is caused by these sorts of 'mistakes'.
- HappyTypist 11y agoIf Dell writes a kernel patch they will fail Windows accreditation and not be able to ship Windows. I think Chrome should treat user CAs as untrusted and require a click wrap before proceeding.
- JoshTriplett 11y ago> I, as the user, want to override HPKP, it should be easy for me to do so. Absolutely. For debugging purposes, browsers should have a mechanism where you can purposefully use your own local certificate, with a big unremovable warning at the top telling you that. It should not, on the other hand, ever look like a valid secure site. No legitimate reason exists for a browser to silently show a site as secure that uses certificate pinning and doesn't serve the pinned certificate. Ever. For debugging purposes, you don't need it to work silently. And if someone started intentionally compromising browsers to make such warnings go away, we'd have a clearer indication that they'd progressed past ignorance into malice.
- maccam94 11y agoI've heard that some corporate networks do this to enable filtering and monitor employee internet usage. I could see that being a somewhat legitimate use case.
- shkkmo 11y agoSo you don't think that the corporate employees have the right to know then their company is doing MITM to monitor their HTTPS traffic?
- euyyn 11y agoI guess if you're using a company's computer on that company's network, assume it's their best interest to monitor some of the stuff.
- itistoday2 11y agoThey can monitor, that's fine, and the correct/ethical thing would be to inform the employees about it and show them a little thing in Chrome to indicate they're being monitored. Informed consent, in other words. pdkl95 also makes excellent point about the current default behavior being the problem: https://news.ycombinator.com/item?id=10630375 https://news.ycombinator.com/item?id=10630375
- deleted 11y ago[deleted]