5 ms·
Most key change events are innocuous, so a key change in and of itself carries much more noise than signal, in the same way most HTTPS errors are not MitM attac
by bascule 10y ago
Most key change events are innocuous, so a key change in and of itself carries much more noise than signal, in the same way most HTTPS errors are not MitM attacks but misconfigurations.
Asking the proverbial Johnny to make a security decision each time happens will result in alert fatigue. The overwhelming majority of users will always accept the new key because they just want the app to work.
They are not a magical panacea that makes MitM attacks go away. There are two good solutions to this for users who care, however:
- Verify keys with each other in person
- Move to Key Transparency / CONIKS-like systems for auditing key servers
- anon1385 10y ago>in the same way most HTTPS errors are not MitM attacks but misconfigurations. It's interesting that you make this comparison. For a while now I've been of the position that web browsers should scrap all TLS user interface stuff (padlocks, green bars, invalid cert warnings, self signed cert warnings etc), because it doesn't communicate any information that the average user can make any use of. It's only one aspect of what makes a site 'secure' for users, and probably one of the far less important ones. The vast majority of attacks on users (info being stolen, malware being served etc) come from the site itself being compromised, not from MitM attacks by their ISP. The vast majority of warnings about bad certs are due to somebody forgetting to update it or config issues, not because of real MitM attacks. The vast majority of people just click through cert warnings. The padlock icon in the browser doesn't even do the one thing it promises since it's no guarantee that TLS is being applied all the way to the actual web server. XSS is a bigger threat to the average user but browsers don't warn about sites that aren't using CSP. My theory is that browser devs always knew the padlock icon was bullshit snake oil, but they implemented it at the demand of the e-commerce industry. At the time it was difficult to get people to trust the web enough to enter their credit card details. Providing a meaningless 'security' icon was needed to bootstrap consumer trust in the industry.
- eridius 10y agoThe padlock isn't meaningless. It means you can submit passwords and credit card details without someone else in the internet cafe sniffing your traffic. The only thing it doesn't do is it doesn't protect you from MitM (or verify the legal identity of the entity you're talking to). The green EV certificate stuff is what's supposed to tell you that you're safe from MitM and phishing, because you can verify the legal identity of the entity you're talking to. Really the biggest problem is browsers like Chrome that use green padlock/text for DV certs, because that's misleading and either makes people trust the DV certs more than they should, or distrust EV certs. Safari does this much better, using a grey padlock (and no other text) for DV certs, and showing Green padlock + green text for EV certs.
- idlewords 10y agoI think you're mistaking the success of TLS for inefficacy.