14 ms·
CA Comodo used broken OCR and issued certificates to the wrong people
- retox 10y agoYet another in the long line of fuckups.
- cordite 10y agoShould being part of a CA include having a red team constantly trying to breach things?
- ethbro 10y agoOr more specifically, do security auditors have red teams authorized as part of their audit?
- thenewwazoo 10y agoIn my limited experience (infosec for a big 4 firm), the answer is no. The audits are done as cheaply and as quickly as possible. I worked alone, in fact, and essentially did process testing (read: document review).
- raesene6 10y agoIt's a plausible suggestion that all services that provide basic critical infrastructure for the Internet (e.g. DNS, Certificate Authorities, ISPs and network providers) should have a very high level of security testing given their attractiveness to attackers. the only problem is... who's going to pay for it? the CA model and the DNS model tend to be a very low-cost one which means there's unlikely to be the kind of money available to pay for expensive red-teaming on a regular basis, let alone running infrastructure that would resist their attacks..
- tptacek 10y agoShould it be? Yes. Is it? No.
- thingexplainer 10y agoWhen will it be?
- brazzledazzle 10y agoWhen enough people are screwed by it to justify the requirement which will justify the resultant cost increases.
- cik 10y agoAnd yet somehow browsers have decided that self-signed certificates are less valuable that purchased ones. Seriously?
- wolf550e 10y agoIf the browser adopts a trust-on-first-use policy with self signed certificates and the certificate is replaced (possibly because it has expired), how do you know whether it's MiTM or benign?
- robryk 10y agoHave a self-signed CA certificate with a longish expiration and sign the actual keys the webservers use with that. Apply TOFU to that CA certificate (on a per-domain basis). There's IIRC no mechanism for that, but for the single-domain CA key it'd make sense to sign the new one with the old one.
- 45h34jh53k4j 10y agoTOFU is bad for the web. Its is much easier to MiTM https vs ssh. Many vendors will sell your enterprise kit to do it to all users. There will be some jurisdictions where MiTM is always and unavoidable. TOFU can't work here. These things must be universal, and TOFU can never be universal.
- LukeShu 10y agoI recall a website with a self-signed cert, but they had a non-https page that had a their TLS cert fingerprint signed with their GPG key; which effectively moved the trust from the centralized CA system to the PGP web of trust. I think it would be cool to have a standard URL (/.well-known/certificate or something) that explains why you should trust their self-signed certificate, and have the browser show that as part of the view when you encounter a self-signed cert.
- 45h34jh53k4j 10y agoThen you have leaked material over http or some other cleartext protocol. If you try to add encryption to that you just have turtles or move the key exchange somewhere else. The current PKI system allows you to make an unsolicited encrypted connections to an internet origin over an untrusted connection with strong server authentication. Self signed can not provide this. We do not want the web to be like SSH.
- deleted 10y ago[deleted]
- longwave 10y agoThe underlying issue here is that WHOIS is still not standardised despite being around for over 30 years, and the registrars do not have any other common interface that can be used to discover domain owners and other metadata. Is there no workable solution to this problem?
- nailer 10y ago> the registrars do not have any other common interface that can be used to discover domain owners and other metadata There's `.well-known` HTTP resources: https://tools.ietf.org/html/rfc5785 https://tools.ietf.org/html/rfc5785 I work for CertSimple and we automatically use `(site)/.well-known/pki-validation` if we see whois privacy, because in practice customers using whois privacy are inevitably uncontactible. We may use `.well-known` by default in future. Our friends at LE/Certbot (ie, ACME) use `(site)/.well-known/acme-challenge`. Also there is various efforts to replace/standardize whois, eg WEIRD and RDAP https://tools.ietf.org/html/rfc7483 https://tools.ietf.org/html/rfc7483. However .well-known resources work well enough for the purposes and in practice is more widely used.
- stephenr 10y agoSo if WHOIS has the correct (matching) business name, you trust that, presumably?
- nailer 10y agoNo. Whois isn't used for identifying legal entities (EV). Just for proving control over a domain (baseline requirements).
- stephenr 10y agoSorry what I meant is proving control of the domain by the specified legal entity. If I apply for an ev cert for ACME Inc to use on acme.com and have "ACME Inc" as the registered owner in Whois, does that satisfy the domain control check?
- ungzd 10y agoSo stupid anti-spam measure — email addresses as image — led (indirectly) to such huge vulnerability.
- Kenji 10y agoI think that is a great anti-spam measure. Most web scrapers are not gonna run OCR on the images of your contact page and you save yourself huge pains and loads of spam. Tell me, what is a better way? Using obscured JavaScript code to inject the address into the page? CSS hacks? HTML comments inbetween parts of the address?
- eli 10y agoA better way is to just list your email address and accept that you will get some spam. My email address is already in plaintext on many webpages and WHOIS entries. It's not that big a deal.
- m8rl 10y agoI have my email address open on most websites I've designed and programmed for decades now, and I don't receive more spam at these address than on at those addresses which aren't public. Spammer harvest for years now using many channels: buying addresses, hacking databases, using viruses stealing complete address books from people. Using images as anti-spam measure really gives you a lot more problems than benefits (except you'd use random single-usage addresses). Don't obfuscate, but fix your spam filters or switch your email provider. What helps a lot is server-side moving of detected spam emails to your junk folder and looking through this folder from time to time.
- extrapickles 10y agoThe only measure I use is a email that is invisible email that adds the sending host to a blacklist right before the plaintext email.
- minitech 10y agoAlso a great way to prevent people who have to use screen readers from seeing it.
- asidiali 10y agoComodo should be put out of business. They stole $100 from me for a certificate then gave me the run around for months while I tried to get a refund for a certificate I never received. Still haven't gotten my money back.
- Avenger42 10y agoChargeback?
- Keverw 10y agoA chargeback is when you dispute the charge with your credit card company, like if you never received your items.
- orf 10y ago> like if you never received your items. Like paying for a SSL certificate you never received?
- Keverw 10y agoYep, sounds like it would be useful for this case. Not sure why people are down voting my answer. The other person posted "Chargeback?" - note the question mark. So I took that as if they were asking what a chargeback is, and was trying to explain it as simplified as possible.
- jdmichal 10y agoYou shouldn't be downvoted, but I do believe you misread the intent. Avenger42 was responding to a post which did not mention "chargeback", so it wouldn't make much sense to interpret it as, "What is a chargeback?". Rather, "Why don't you use a chargeback?" would seem to be a better interpretation.
- Avenger42 10y ago
- johnwheeler 10y ago+1 for https://letsencrypt.org https://letsencrypt.org
- hosh 10y agoI remember reading through the forum post for that letsencrypt bruhahaha when Comodo filed for trademark infringement on Letsencrypt. The CEO seemed really self absorbed and saw himself as an innovator with letsencrypt stealing business processes from him (which makes filing for trademark infringement make less sense). He took it as a personal insult, and did not even appear to understand that letsencrypt was a public service rather than a for-profit product. There was a fan who claimed to be a paralegal cheering on the CEO's rant yet appeared to confuse trademarks with patents with copyrights. At least with the forums alone, that thread read like teenage high school soap opera, not a business. It was like an echo chamber of the CEO's fixation. And now this. Sounds like there was a deliberate business decision to use faulty tech, and forgetting the wider social impact of operating a CA.
- maket 10y agoHere's the forum post in question https://forums.comodo.com/general-discussion-off-topic-anything-and-everything/shame-on-you-comodo-t115958.0.html;msg837411#msg837411 https://forums.comodo.com/general-discussion-off-topic-anyth... Here's the HN discussion https://news.ycombinator.com/item?id=11964583 https://news.ycombinator.com/item?id=11964583
- victor9000 10y agoI recently replaced an expired cert with one from LE and the entire process was super simple. Their cli automatically handles all the tedious steps like creating the signed request, proving server ownership, and creating the certificate bundle. What's more, it also provides tools for renewing certs in an automated way. I really can't see myself using anything else from here on out.
- amelius 10y agoLast time I checked the LE cli tool required root access to my machine. Totally annoying and unnecessary. Otherwise, I applaud the initiative.
- djsumdog 10y agoUniversities that are part of InCommon paid to get unlimited Comodo SSL certs. Their API was pretty terrible and we ended up finding quite a few issues. Every time I hear about these Comodo breaches, I'm not surprised. Supposedly, Iran was able to get them to issue fake certs for some major sites: http://www.pcmag.com/article2/0,2817,2382518,00.asp http://www.pcmag.com/article2/0,2817,2382518,00.asp
- deleted 10y ago[deleted]
- orf 10y agoIsnt this is the same company that produced a 'secure' browser that disabled CORS? Doesn't surprise me.
- 45h34jh53k4j 10y agoThey also make the best free application firewall software for Windows. Its unrivalled for features in this space. Nothing exists like this for linux (however https://github.com/subgraph/fw-daemon https://github.com/subgraph/fw-daemon is getting close). The quality of the software both good and bad doesnt' apply here.
- orf 10y agoIs this sarcastic? I can't tell. How is it unrivalled, and why would you trust it coming from a company with an abysmal track record of security? Just Google 'Comodo Project Zero' for a taste. Or read this[1], one of the bad ones. Also whats wrong with ufw? Github is down so I can't view that link. > The quality of the software both good and bad doesnt' apply here. Well I clearly does, because this post is about how their software did some crazy roundabout stuff to validate domains that didn't work. 1. https://bugs.chromium.org/p/project-zero/issues/detail?id=769 https://bugs.chromium.org/p/project-zero/issues/detail?id=76...
- 45h34jh53k4j 10y agoufw, and by extension iptables, lacks features such as per process rules. You have to do hacks like assign rules to users, and run the processes under different users. Tails does this to isolate the Tor Browser process. When you check out the link, see that nothing like this exists on linux. The closest thing on OSX would be little snitch. github isnt down, flush your dns, its left over cached NXDOMAINS from this mornings outage. you can also clear your browser dns cache with chrome://net-internals/#dns I think my original meaning is there is lots of teams and not all of them are bad :-)
- orf 10y ago
- zokier 10y agoMore worrying than some OCR silliness is that Comodo is issuing certificates based solely on WHOIS data. I don't think it is intended for such security critical use.
- 45h34jh53k4j 10y agoIf you read the report linked from the bugzilla, you will read: One of the methods that Comodo uses to validate that a certificate applicant owns or controls a domain to be included in the subjectAlternativeName of a server authentication certificate is set out in the CA/B Forum's Baseline Requirements document [2] at section 3.2.2.4.2. That method may be summarized as the sending of an email to an email address (and obtaining a confirming response) where the email is identified as belonging to the Domain Name Registrant, technical contact, or administrative contract as listed in the WHOIS record of the domain. So the Browser (Google Mozilla Microsoft) and the CA (Comodo Symantec LE) industry working group agreed that was acceptable.
- zokier 10y agoMaybe it is time to review that policy. As far as I can tell, WHOIS protocol and data are both completely unauthenticated, and as such relatively easily manipulated by mitm.
- 45h34jh53k4j 10y agoRDAP over https should be fine
- zokier 10y agoAnd if RDAP or whatev would have been used here then the whole problem would have never occurred. But it wasn't, due not being required to. Ergo sum, the requirements should be reviewed to avoid repeating this sort of thing.
- pfg 10y agoBaseline Requirements also allow domain validation via DNS or a HTTP request. Essentially all domain validation methods break down once you're in a position to MitM the CA.
- ig1 10y agoPreviously from Comodo: http://www.pcworld.com/article/2887632/secure-advertising-tool-privdog-compromises-https-security.html http://www.pcworld.com/article/2887632/secure-advertising-to...
- bandrami 10y agoHow people still think the PKI system is actually delivering security is beyond me. We have zero idea how many bad certs like this may be out there (the nefarious people won't publish their results, after all), and yet a browser will still treat a Comodo cert as better than a self-signed one (it's identical to a self-signed cert, since Comodo is a known bad actor now). It's better than plaintext, of course, but that's not saying much.
- 45h34jh53k4j 10y ago"Dont throw the baby out with the bathwater." We have certificate transparency, the browsers are more responsive and reporting, we have HPKP and other browser countermeasures. Its not perfect but with enough eyeballs it can get close. It provides meaningful security. CA signed clearly not the same as self-signed; Maybe you misunderstand what this means?
- bandrami 10y agoCA signed clearly not the same as self-signed How is a certificate from Comodo any different from an self-signed certificate? There is actual evidence that they gave a certificate to a third party. That means you should treat any certificate from them as self-signed, because you cannot trust Comodo to do their jobs.
- 45h34jh53k4j 10y agoAssuming you understand the structural difference between a self signed and a CA signed certificate (ie: subject pubkey sig vs issuer pubkey sig respectively) the difference is clear. You cannot determine provenance of a self-signed certificate. The sig matches the subject. With a CA signed, the hold of the CA private key is the only source (with high probability), so it is attributable. If you trust the company or not -- play with you trust store. Otherwise this is apples and oranges. The only time when this comparison would be apt would be the compromise of the Comodo Private Key. This would allow anyone to issue Comodo certificates, thus removing their provenance. Of course then their cert would be revoked and we wouldn't have this conversation.
- codegeek 10y agoI am usually not good with donations but one company that I gladly donated to has been letsencrypt. They have made life so simple. Please donate[0] or become a sponsor[1] if you can. [0] https://letsencrypt.org/donate/ https://letsencrypt.org/donate/ [1] https://letsencrypt.org/become-a-sponsor/ https://letsencrypt.org/become-a-sponsor/
- asymmetric 10y ago+1. Only nitpick is that LetsEncrypt is a nonprofit, not a company.
- an_account 10y agoNonprofits are companies...
- criddell 10y agoNonprofits are still corporations. LetsEncrypt is a service of Internet Security Research Group: https://letsencrypt.org/isrg/ https://letsencrypt.org/isrg/ ISRG is a Secion 501(c)(3) corporation.
- chetanahuja 10y agoWeb security based on PKI model based on 100's of "trusted" authorities is just broken. And yet, the "security industry" continues doubling down on "moar TLS" "moar green locks" model instead of coming up with a better model. The tragedy is, that most of the internet access is now happening from mobile devices and majority of that is coming from native apps. The apps need neither the same trust model nor have any "green locks". But PKI/TLS based orthodoxy has such a death grip on the industry that people continue to use this broken model for native apps where it makes even less sense than it does for browsers.
- corecoder 10y agoWell, unless apps authors are writing their HTTPS clients from scratch, I suppose major mobile OSes provided HTTP client API functions do actually check certificates?
- advisedwang 10y agoI think chetanahuja is saying apps don't have to rely on CAs. They can distribute a single trusted certificate, only trust a single CA or use key pinning.
- Aaron1011 10y agoYou can still promote using TLS while recognizing the flaws in the current PKI-based authentication system. From a purely technical perspective, a TLS connection without authentication is still better than no encryption at all.
- thingexplainer 10y agoAnd yet there are millions of people using the Internet and we have to protect them with the army we have. I hope we'll see something like Marlinspike's Notaries becoming widespread in our lifetime, though.
- thingexplainer 10y agoAnd yet there are millions of people using the Internet and we have to protect them with the army we have.
- andrewmcwatters 10y agoHave CAs always been this sloppy or are we just hearing about it more nowadays?
- lucb1e 10y agoAs the system grows I think there are more and more players, competing for market share, trying to get low prices and high profits, and more shit happens as a result. On top of that, since it's getting more and more important, we also hear about it more.
- icebraining 10y agoBrowsers have been adding checks (like pinning) that catch some of the faulty certs, whereas before this was much harder to detect.
- oxguy3 10y agoFor the love of God, why has Mozilla not suspended Comodo yet? Too big to fail, my ass -- give a few months of warning before the notBefore cutoff date, and everyone will have plenty of time to switch over to a competent CA.
- __jal 10y agoSeriously. How many times has Comodo displayed terrible judgement? Bugs happen. Stupid bugs happen. Stupid systems with stupid bugs even sometimes happen. What I don't see is Comodo learning anything from their serial screwups.
- NelsonMinar 10y agoComodo has had many serious security problems, including issuing fraudulent SSL certificates and releasing browser extensions that break security. Details: https://news.ycombinator.com/item?id=11962371 https://news.ycombinator.com/item?id=11962371
- ComodoHacker 10y agoI'd like to know how other CAs perform domain validation for .be and .eu TLDs. Disclaimer: not associated with Comodo in any way.
- flavmartins 10y agoI work for one of the big CAs out there. For those domains a human actually performs a manual WHOIS query for those TLDs and then manually enters in the email address associated with the domain contact and they are required to include a screenshot of the WHOIS details for verification of the information. A second individual then is required to perform a verification that the email address entered is correct per the attached screenshot. All of this, plus the querying of the organization's legal registration, business address and contact is all done by trained people and due to internal efficiencies and workflows we can complete that in a matter of minutes from the time a customer places an order. In the end, even an organizational vetted certificate is still completed just as fast as it takes customers usually to click on the approval email to authorize issuance and submit the CSR for the certificate creation.
- ComodoHacker 10y agoSo it's a matter of cutting costs for Comodo. Thank you.
- thingexplainer 10y agoHave you considered generating these screenshots automatically? It seems like if you did, this would protect you against both typos and insiders.
- kl4m 10y agoThey may actually do it manually.
- xnyhps 10y agoI'd expect HTTP, DNS based or email to {hostmaster,postmaster,etc.}@domain validation to be more common than validation based on WHOIS data. There are probably very few domains for who only the WHOIS based validation is doable.
- drumttocs8 10y agoComodo is awful. I remember loving their original products, but it's been downhill ever since they started trying to monetize so heavily.
- taurath 10y ago>The OCR has a reproducible bug and has trouble differentiating small l and the number 1. It also has trouble differentiating the number 0 and the small o. Instead of fixing the bug or not using such obviously unsuitable software the software apparently evaluates the following characters - if there is a number after the small l it reads the l as the number 1. Similar issues with o/0. So what they're saying is y0u can fo0l their servers with 1eetspeak?
- darklajid 10y agoI mean - these 'fixes' are common as far as I can tell (working in/around OCR). But then again - I'm not issuing certificates. Quite often you try to eliminate uncertainty by being clever: Sure, OCR engine: Go ahead and recognize O and l and B if you want. If I know that the context of this text is an amount, I'll still replace those chars with 0 and 1 and 8 afterwards. (Engines usually allow you to configure the allowed character set, but in practice it seems to be easier/more reliable to work like a parser: Lenient in what you accept and strict in what you pass on)
- siculars 10y agoYou intervene with humans when you detect /1io0/i.
- emodendroket 10y agoI'm always amazed at how many Kindle books you buy have clearly not gone through a simple spell check to catch errors like these.
- thebakeshow 10y agoDid you mean l33t5p4ak?
- omouse 10y agoNot surprised, they seem like a shady outfit.
- Johnny555 10y agoDid Comodo admit to using OCR for this, and that it wasn't a human transcription mistake (humans mistake 1's and l's too) It just seems odd for them to use an image of a web page to transcribe information from a web lookup when they could just scrape the text off the web page directly without using the intermediate image and OCR. However, I could see them using a human in the chain to look up the whois information, it just seems strange to come up with a complicated OCR solution (and if they did, that they couldn't find a font that makes 1's and l's look more distinct, like http://forum.high-logic.com/viewtopic.php?t=4004 http://forum.high-logic.com/viewtopic.php?t=4004)
- wongarsu 10y ago>when they could just scrape the text off the web page directly without using the intermediate image and OCR Try looking up whois info on google.eu. Most tools will simply output `NOT DISCLOSED! Visit www.eurid.eu for webbased whois.`. Now you can search https://whois.eurid.eu https://whois.eurid.eu for the whois information of google.eu. You will find that the email address is only available as an image. That's exactly the situation Comodo tried to solve. Given that it's a simple font with no obfuscation, a small pattern-matching python programm should give you near 100% accuracy. Apparently Comodo used some off-the-shelf software instead, and that software seems to make assumptions it shouldn't make.
- Johnny555 10y agoAhh interesting, so it's a case of the cure being worse than the disease -- spammers know how to use OCR too and they don't care about transcription errors. So it seems like there's little point in deliberately obscuring the email address in an image, and certainly no reason to do it with a font that doesn't more clearly distinguish between letters and numbers.
- technion 10y ago.com.au domains have the same issue. Every contact is: Visit whois.ausregistry.com.au for Web based WhoIs I wonder if Comodo had a similar issue there.
- nneonneo 10y agoRelevant mailing list post: https://www.mail-archive.com/dev-security-policy@lists.mozilla.org/msg04654.html https://www.mail-archive.com/dev-security-policy@lists.mozil... In this email, Comodo discloses the security issue to Mozilla. The email was sent 26 days after researchers Florian Heinz and Martin Kluge of Vautron Rechenzentrum AG informed them of the bug. Comodo clearly states that they used OCR for .eu and .be domains because the TLD registrars redacted their port 43 WHOIS data, and only provided an image of an email address on their web WHOIS pages. There was apparently no other way to obtain the email address. Rather than flag humans to fix OCR in ambiguous situations, they had automated heuristics to correct the OCR, as determined by the security researchers. However, the heuristics chose the wrong output for the domain @a1telekom.at, producing @altelekom.at (an L instead of a one). The researchers registered altelekom.at and obtained a cert for a domain owned by A1 Telekom, a major ISP.
- Pyxl101 10y agoThere is an accusation in the comment thread of the article that Comodo only disclosed this issue to Mozilla after it was reported publicly by the news media. > steffen 2016-10-20 08:35:58 PDT > In fact, the linked incident report refers to the heise article I also linked. So Comodo chose to "publish" this immediately after it was made public by others. That would be quite a coincidence. This raises the question of whether Comodo would've informed Mozilla at all if the media hadn't picked up on it.
- dfeart3453465uf 10y agoA lone security researcher can find a bug and write it and share up a lot more quickly than corporation. Corp has to write, test, verify, share internally, review and approve before it can be released. Bureaucracy. They also needed to patch their systems too. Ryan Sleevi (Google) asked the question, and Robin Alden (Comodo) stated a reasonable timeline. There is no conspiracy here.
- garaetjjte 10y agoHow even whois verification works? It don't contains email of domain registrar, not registrant?
- abricot 10y agopranjalv123 called it: https://news.ycombinator.com/item?id=6620467 https://news.ycombinator.com/item?id=6620467