4 ms·
That's actually a possibility but I very much doubt this would be used in practice. Apart from the scaling problem there is a more serious problem which would
by maulwuff 10y ago
That's actually a possibility but I very much doubt this would be used in practice. Apart from the scaling problem there is a more serious problem which would make use of this certificate for lots of MITM impossible:
- today's browsers use certificate pinning, i.e. Chrome, Firefox... have predefined lists of sites where they know which public key to expect. One example of such a site is google.com.
- The browser will usually complain if the certificate for this site is not the expected one.
- The browser will not complain on pinned certificates if the CA issuing this certificate was explicitly added as trusted into the browser. This is to allow legal SSL interception, i.e. the one done in lots of companies to protect against malware and data leakage and done by several desktop AV products for the same reason.
Thus, if the certificate is signed by the BlueCoat CA which is implicitly trusted due to derived trust then the browser will complain because the certificate does not match the expected (pinned) one. If instead the certificate was signed by an explicitly installed CA the browser will not complain.
That's actually the way the usage of misissued certificates in Iran was detected (ComodoHacker). So this behavior would make the use of this BlueCoat CA for many MITM attacks impractical.
- prdonahue 10y ago> today's browsers use certificate pinning, i.e. Chrome, Firefox... have predefined lists of sites where they know which public key to expect. One example of such a site is google.com. Yes, this may be true, but the list is quite small. You may not be able to trick Chrome into connecting to a fake google.com certificate but there's lots other "high security site[s]" as Adam Langley suggests[1] should apply when they opened this up: > Can I get this for my site? If you run a large, high security site and want Chrome to include pins, let me know. The reason why this list is small is because key pinning in practice is difficult — and risky. Look to comments on Twitter from Sleevi et al. as to how easy it is to shoot yourself in the foot. HPKP is a terrific idea, but has complicated implementation challenges. [1] https://www.imperialviolet.org/2011/05/04/pinning.html https://www.imperialviolet.org/2011/05/04/pinning.html
- maulwuff 10y agoWhile the list is definitely incomplete I would not call it small. Have a look at https://chromium.googlesource.com/chromium/src/net/+/master/http/transport_security_state_static.json https://chromium.googlesource.com/chromium/src/net/+/master/...
- throwaway2048 10y agoits easy to discover whats on the list by people doing mitm...