4 ms·
A state sponsored attacker can reasonably easy generate a valid ssl certificate to man-in-the-middle any website, and replace it with what ever they please. How
by grapehut 10y ago
A state sponsored attacker can reasonably easy generate a valid ssl certificate to man-in-the-middle any website, and replace it with what ever they please. However, they wouldn't be able to forge a signature if checked against the right keys
- xyzzyz 10y agoThe point here is that how can you make sure the keys are right, if the attacker might also replace those?
- schoen 10y ago> A state sponsored attacker can reasonably easy generate a valid ssl certificate to man-in-the-middle any website, and replace it with what ever they please Doing this against bitcoin.org is probably taking a pretty big risk. Remember that misissued certificates represent proof of their own existence, and, if disclosed publicly, should result in an investigation of how the certificate was created. They could also choose to start using HPKP and asking browsers to report pin failures. Then a browser that has visited the legitimate site before will report to someone if it encounters an inconsistent cert in the future. That would make using a misissued cert for this site into an even bigger risk. https://en.wikipedia.org/wiki/HTTP_Public_Key_Pinning#Reporting https://en.wikipedia.org/wiki/HTTP_Public_Key_Pinning#Report...
- chrisfosterelli 10y ago> Doing this against bitcoin.org is probably taking a pretty big risk. Although it wasn't by hijacking the public key infrastructure, it is worth noting that China has demonstrated in the past they have no issue performing country-wide man-in-the-middle attacks against a single site [1]. Given that some CA's are Chinese, it is not that unbelievable unfortunately... [1]: http://www.pcworld.com/article/2908912/chinas-great-cannon-ddos-tool-enforces-internet-censorship.html http://www.pcworld.com/article/2908912/chinas-great-cannon-d...
- JoshTriplett 10y agoTrue, but that attack used an HTTP resource. An HTTPS MITM attack burns a CA; browsers will remove it from their trust stores. And we're getting close to the point that it can't go undetected, either; once browsers enforce Certificate Transparency for all CAs, it'll no longer be possible to conduct an undetected MITM attack.
- jessaustin 10y agoDoing this against bitcoin.org is probably taking a pretty big risk. Anyone who can escalate into stealing BTC, can afford that risk.
- ryan-c 10y agoWhen I was looking into Chinese browsers two years ago, a number of them did not correctly validate certificates on HTTPS sites. They might not need to burn a CA. It should also be noted that HPKP will ignore issues when the cert is signed by a locally installed CA.
- jtl999 10y agoIt won't ignore issues for when the CA chains back to a OS preloaded one (when there is a distinction between user-added and preloaded, not sure in other case. ie Linux.) I agree somewhat more could be done on this front however if you're in a position where an adversary can add user-added CA's to your system you have bigger problems to worry about.