3 ms·
I think the point the parent was making is that it is likely that one or more of the most prevalent certificate authorities' private keys have been compromised
by developer2 10y ago
I think the point the parent was making is that it is likely that one or more of the most prevalent certificate authorities' private keys have been compromised - whether voluntarily provided to government, or obtained by criminals via dubious methods.
Once the private keys are compromised, all bets are off. No database - whether maintained by Google or anyone else - puts a dent in such a problem. It's one thing to track inauthentic certificates; it's quite another to discover someone silently decrypting traffic with a copy of the private key.
Edit: My response brings up an interesting question I hadn't considered before. With the certificate chain, is it required to have the private keys for the entire chain in order to be able to decrypt the stream? If someone has the certificate authority top-level certificate, can they decrypt a domain's certificate without having its private key as well as any intermediates? If not then it'd be true that the primary concern with a top-level private key being compromised is illegitimate certificates being signed, in which case Google's attempt to combat that with Certificate Transparency isn't half bad.
- jakewins 10y agoYour edit is correct - it is the public certificate that is signed, so a cert authority never sees the private cert and can hence not decrypt downstream. The problem is issuing fake certificates.
- nikital 10y agoAs far as I know, you can't trivially decrypt traffic as a passive observer, even if you have the private key of the website or the CA. The sides still perform key exchange using something like Diffie-Hellman. The asymmetric keys are used to verify that you're performing the key exchange with the real server and not with a MITM. If you have the CA's private you must sign your own fake certificate and MITM the connection with the fake certificate. In this case, as you pointed out, Certificate Transparency does help because the fake certificate won't be present in the certificate logs.