3 ms·
Cure53's report details a complete bypass of WebSign as implemented, as well as stern warnings against relying on a non-security feature for security.
by sdevlin 11y ago
Cure53's report details a complete bypass of WebSign as implemented, as well as stern warnings against relying on a non-security feature for security.
- buu700 11y agoNot denying the increased attack surface, but that bypass was immediately fixed and verified by Cure53 (so no known vulnerabilities exist); furthermore, as you'll see in both our foreword to that report and the linked reddit comment, the current version of WebSign actually no longer has that general flaw. Breaking WebSign would require defeating TLS public key pinning (which is a security feature), thanks to the technique that an email I just received so perfectly referred to as "HPKP suicide".