4 ms·
The appliance itself doesn't seem that important. The big thing I take from the article is law enforcement needs to: "persuade one of the Certificate Authoritie
by jimdeterman 17y ago
The appliance itself doesn't seem that important. The big thing I take from the article is law enforcement needs to: "persuade one of the Certificate Authorities — using money, blackmail or legal process — to issue a fake certificate for the targeted website." If you can get a forged certificate from a trusted cert provider, then there is a bunch of ways to do this. The box is just a convenience.
- Titanous 17y agoLooks like all it does is replace a SSL MITM proxy.
- stcredzero 17y agoThe real bad guys can just use symmetric encryption, with keys distributed by mail or by hashing parts of certain books. It's the typical end-user going to their banking site or reading their email that's most vulnerable to such devices. China might be a top customer.
- Titanous 17y agoPublic-key encryption (such as PGP) would work as well.
- eru 17y agoOr rather Off-the-record messaging: You do not want deniability, and not leave provable traces.
- tptacek 17y agoIf the real bad guys are smart, they're just going to use SSL, with a single static private CA.
- agentq 17y agoWhat will end up happening to the 'real bad guys' http://xkcd.com/538/ http://xkcd.com/538/
- billybob 17y agoYes - I thought this was a cryptographic breakthrough, but it's just people breaking promises.
- orangecat 17y agoThat, and it demonstrates how bad the default SSL trust model is. If the gmail.com certificate came from Thawte yesterday and comes from the Department of Defense or CNNIC today, your browser will happily accept it without warning.
- bkudria 17y agoIf a CA is compelled to issue a false certificate by court order, this destroys their credibility completely. If I ran a CA, I'd rather face the consequences, and let the court ask another listed CA, rather than destroy my entire business model.
- tptacek 17y agoWatch what happens when we find out which CA's did this. My money is on "they do not go out of business". Give it a few months.
- olefoo 17y agoEspecially with Americans new found willingness to accept overreaching law enforcement measures. So long as one of the right trigger words (terrorism, children) is used, the average purchaser of certificates won't blink at the idea that law enforcement completely subverted the chain of trust that enables their customers to believe they are dealing with who it says on the certificate.
- ars 17y agoCourt order? Your argument might make sense if it was law enforcement making the request. But do you really think companies should ignore court orders?