4 ms·
With the SSL-subversion boxes mentioned in http://www.wired.com/threatlevel/2010/03/packet-forensics/ http://www.wired.com/threatlevel/2010/03/packet-forensics/
by dkimball 17y ago
With the SSL-subversion boxes mentioned in http://www.wired.com/threatlevel/2010/03/packet-forensics/ http://www.wired.com/threatlevel/2010/03/packet-forensics/ , I don't think it matters who's on the list (though I'm sure China is). A small company selling devices to intercept SSL means that the whole concept is dead. Even if no one else can acquire their devices, the whole world (that cares to find it out) now knows that such a man-in-the-middle attack is possible, so it's just a matter of time before they become much more common.
Worse yet, the company that makes these boxes advertised them at "the world's largest gathering of North American, Caribbean and Latin American Law Enforcement, Intelligence and Homeland Security Analysts and Telecom Operators responsible for lawful interception, electronic investigations and network Intelligence gathering." Any Mexican drug lord worth his cocaine money (or, of course, FARC) will now start bribing or scaring some suitable official into handing over a box or two.
Hopefully we'll discover an alternative approach to ensure online security. Just having fewer, more reliable CAs would be enough -- although, as I pointed out elsewhere, the measure of security is ultimately boots on the ground, not code in the aether.
Update: You're right, there's a trusted Chinese CA. From the Wired article: "[w]hen Mozilla added a Chinese company, China Internet Network Information Center, as a trusted Certificate Authority in Firefox this year, it set off a firestorm of debate, sparked by concerns that the Chinese government could convince the company to issue fake certificates to aid government surveillance."
- qjz 17y agoThe number of CAs doesn't matter. The essential flaw in SSL is that once you trust a CA, you trust it for all sites. This is what makes a MITM attack so trivial for someone who is well positioned in a network, and these appliances just make it that much easier to deploy if you don't have all the skills yourself. Another problem is the sheer conceptual complexity of the system. It wouldn't take much to convince your boss to let you purchase an "SSL proxy" to fight viruses and commercial espionage, when all you really want is to steal all his passwords.