3 ms·
How will these websites communicate #3? Through the blocked website?
by phaed 10y ago
How will these websites communicate #3? Through the blocked website?
- tedunangst 10y agoObviously they get another cert, but only serve it to chrome users via SSL handshake fingerprinting, and serve the Symantec cert to everybody else...
- wtetzner 10y agoI can't tell if you're joking. Just in case you're not, if they went through all the trouble to get another cert for Chrome, why wouldn't they just use it for everyone?
- agwa 10y agoI suspect it was a joke, but you raise a very important question. Unfortunately, some clients (likely embedded devices) trust only Symantec roots, since that's the CA the website was using at the time the developer slapped together their code.
- CountSessine 10y agoWouldn't they just do what all browser-version-specific websites have done in the past and have an http landing page with a conditional redirect? User agent is IE6, and you progress to ie6.bankofamerica.com. User agent is Chrome/Firefox, progress to webpage with browser version warning and download link for IE6.
- tedunangst 10y agoMaybe after their HSTS header expires. What do they do until then? Or for all the users with https bookmarks?
- CountSessine 10y agoWell, just looking at the Bank of America example, they don't seem to use HSTS in their landing page. How widespread is HSTS? How long is the expiry period typically set for (I would guess a long time?) Does anyone still use browser bookmarks? Actually, just thinking about it, it might be even simpler than this. If Bank of America wanted to, couldn't they still host their redirect landing page over SSL with a valid non-Symantec certificate, and then redirect to the ie6.bankofamerica.com page which will continue to use the bad Symantec cert? If switching certs for their web infrastructure was really difficult and they didn't want to do it, they could just build a simple little front-end web server with a valid certificate to redirect people to an IE6 download page or ie6.bankofamerica.com.
- Shanea93 10y agoHSTS is currently used by 2.8% of all websites, up from 1.2% this time last year. [1] If people are using Qualys SSL Labs tool to check their "grade", they won't be awarded an A+ grade unless their HSTS max-age is at least 6 months [2], so I'm going to assume the average is somewhere close to that due to how common usage of that tool is. My grandma still uses browser bookmarks, but I have no none-anecdotal source for this. BoA could absolutely do all the things you just mentioned, but all of them are more difficult than simply replacing their certificate using Comodo or some other trusted root CA. [1] https://w3techs.com/technologies/details/ce-hsts/all/all https://w3techs.com/technologies/details/ce-hsts/all/all [2] https://community.qualys.com/thread/15972 https://community.qualys.com/thread/15972
- ethbro 10y agoOn the plus side, it would probably break the Mint / fintech scrapers for a bit...
- CountSessine 10y agoBoA could absolutely do all the things you just mentioned, but all of them are more difficult than simply replacing their certificate using Comodo or some other trusted root CA. That depends on the design of the site and their business policies. I agree though - for any sensible organization switching certs is going to be easier. But if that was really the case here, why were they asking Symantec for special favours?