3 ms·
There's a big difference in attitudes between browsers here. Take OCSP for example - Chrome disabled OCSP because in optional mode it wasn't a perfect solution
by problems 9y ago
There's a big difference in attitudes between browsers here.
Take OCSP for example - Chrome disabled OCSP because in optional mode it wasn't a perfect solution and they didn't want to enable it in required mode because that could confuse the poor users. After the heartbleed attack, Chrome was only able to bundle a tiny fraction of the certificates into their CRLs - leaving millions of domains still vulnerable to blacklisted certificates. On Chrome - you're just screwed, there's no way to turn OCSP into required mode to prevent such attacks.
On Firefox however you're able to force OCSP required - making it actually useful if you're sophisticated enough to understand what a failure of it may mean and you're actually able to blacklist all of those certificates. A huge security benefit in such a case.
- wfunction 9y agoEdit: I'm wrong. Removing this comment regarding why certificate revocation checking is still useful, because someone pointed out you can create a new account to get a new certificate from a CA, and I didn't realize it was that easy to just sign up for a new account. (I was thinking of EV certificates mostly so I didn't think of this attack vector at all.) See [1] for background. Thanks all for pointing that out. [1] https://www.imperialviolet.org/2014/04/19/revchecking.html https://www.imperialviolet.org/2014/04/19/revchecking.html
- problems 9y agoI think he's actually right about the attacker being near you most of the time - compromising a data center is much harder than compromising a LAN most of the time. However, he completely ignores the fact that some users may be sophisticated enough the handle the hard-fail scenarios mentioned. Well, I am. And so are many others. So what am I supposed to do if I want security and can handle hard-fails? Not use Chrome seems to be the answer. Chrome fails to account for power users and developers who would rather have improved security and functionality.
- tptacek 9y agoWhat's your alternative? A customized Chromium fork? Every other browser is markedly less secure than Chrome. If exploit resilience is all you care about, you can theoretically use Edge, but now you're throwing away a lot of important TLS policy stuff that Chrome does and Microsoft is years behind on.
- problems 9y agoFirefox - they're years ahead on this sort of stuff. Their about:config gives you immense power to configure your browser to behave exactly how you want it to. Unlike any other browser around really. The flexibility this brings you in privacy gains alone is immense. Just try to do something as basic as turn off WebRTC in Chrome and you'll see what I'm talking about. Firefox is the only viable answer if you care about privacy and security and have the ability to take things into your own hands.
- pfg 9y ago> And to install a specially formed page on the site, you still need to be able to GET a copy of that page to install in the first place, and how the hell are you going to do that without ALSO stealing their CA login credentials, which I'm pretty damn sure will NOT be stored on every single random server you hack? The ability to answer arbitrary HTTP requests on a server is sufficient to get a publicly-trusted certificate from any number of CAs. You do not need the credentials for the CA they've been using. Just create a new account. Future extensions for the DNS CAA record[1] might be able to help against this if you keep your credentials away from your web server. [1]: https://datatracker.ietf.org/doc/html/draft-ietf-acme-caa https://datatracker.ietf.org/doc/html/draft-ietf-acme-caa
- wfunction 9y ago> The ability to answer arbitrary HTTP requests on a server is sufficient to get a publicly-trusted certificate from any number of CAs. I'm saying you have to know what response to GIVE, don't you? You can't just give a random response...
- problems 9y agoThe CA tells you what response to give on that new account you signed up.
- wfunction 9y agoThanks, that didn't occur to me since I was mostly thinking of EV certs for some reason.
- pfg 9y agoThere's nothing to stop you from creating a new account at the CA of your choice, asking for a validation token, and putting it wherever it needs to be.
- tptacek 9y agoWithout widespread adoption of a must-staple extension, OCSP is cosmetic. The decision to disable it didn't come from simplicity fascists; it came from people like Adam Langley. AGL isn't right about everything, but if you take the position that something he does with Chrome TLS is ludicrous, my default will be that you don't understand the issue as well as he does.
- problems 9y ago> Without widespread adoption of a must-staple extension, OCSP is cosmetic. The decision to disable it didn't come from simplicity fascists; it came from people like Adam Langley. AGL isn't right about everything, but if you take the position that something he does with Chrome TLS is ludicrous, my default will be that you don't understand the issue as well as he does. Well, please, do explain where I'm mistaken here - is OCSP required not the most secure option? And it was rejected simply due to usability reasons on Chrome? And the option to do so anyways for power users doesn't exist because Chrome is a browser for ease of use? I'm not saying it's entirely ludicrous - for a good chunk of the user base CRLs are at least decent - but having an option for power users who desire more security should be available. And it's mandatory for any browser that wants to be used by power users. Stop with the appeals to authority and make an actual argument if you disagree.
- tptacek 9y agoI don't understand the questions you're asking here, but, no, OCSP wasn't disabled simply due to usability reasons, but rather because it did not work.
- problems 9y agoIt works just fine if you require an OCSP response and hardfail. Soft-failing is for usability and it's the cause of the problem. Yes, must-staple is the optimal solution, but OCSP required is the best available today. Look at some of the numbers here: https://www.grc.com/revocation/crlsets.htm https://www.grc.com/revocation/crlsets.htm