6 ms·
Edit: I'm wrong. Removing this comment regarding why certificate revocation checking is still useful, because someone pointed out you can create a new account t
by wfunction 9y ago
Edit: I'm wrong. Removing this comment regarding why certificate revocation checking is still useful, because someone pointed out you can create a new account to get a new certificate from a CA, and I didn't realize it was that easy to just sign up for a new account. (I was thinking of EV certificates mostly so I didn't think of this attack vector at all.) See [1] for background.
Thanks all for pointing that out.
[1] https://www.imperialviolet.org/2014/04/19/revchecking.html https://www.imperialviolet.org/2014/04/19/revchecking.html
- problems 9y agoI think he's actually right about the attacker being near you most of the time - compromising a data center is much harder than compromising a LAN most of the time. However, he completely ignores the fact that some users may be sophisticated enough the handle the hard-fail scenarios mentioned. Well, I am. And so are many others. So what am I supposed to do if I want security and can handle hard-fails? Not use Chrome seems to be the answer. Chrome fails to account for power users and developers who would rather have improved security and functionality.
- tptacek 9y agoWhat's your alternative? A customized Chromium fork? Every other browser is markedly less secure than Chrome. If exploit resilience is all you care about, you can theoretically use Edge, but now you're throwing away a lot of important TLS policy stuff that Chrome does and Microsoft is years behind on.
- problems 9y agoFirefox - they're years ahead on this sort of stuff. Their about:config gives you immense power to configure your browser to behave exactly how you want it to. Unlike any other browser around really. The flexibility this brings you in privacy gains alone is immense. Just try to do something as basic as turn off WebRTC in Chrome and you'll see what I'm talking about. Firefox is the only viable answer if you care about privacy and security and have the ability to take things into your own hands.
- tptacek 9y agoVirtually nobody who works in browser security agrees with you about that. There are privacy wins to be had with Firefox, but they come at the expense of security.
- problems 9y agoThat's a pretty big claim, one which I'm guessing you're offering absolutely no evidence to back up?
- tptacek 9y agoCompare the market prices for equivalent vulnerabilities in Chrome and Firefox.
- problems 9y agoWouldn't that value mostly be based off popularity? Chrome is vastly more popular than Firefox - therefore it's less valuable to exploit a smaller number of users.
- tptacek 9y agoNo. Less popular browsers are also more expensive than Chrome, and the price difference isn't even close to linear. The fact is that Chrome exploits are much harder to write and command a higher price. Start here: https://medium.com/@justin.schuh/securing-browsers-through-isolation-versus-mitigation-15f0baced2c2 https://medium.com/@justin.schuh/securing-browsers-through-i...
- problems 9y agoThat link makes no mention of comparative exploit price, is that the correct one? It doesn't even contrast security features with Firefox... Fact is, exploit price is a crappy way to do such a comparison, there are too many other factors that can play into it - like what browsers companies and governments have deployed.
- pfg 9y ago> And to install a specially formed page on the site, you still need to be able to GET a copy of that page to install in the first place, and how the hell are you going to do that without ALSO stealing their CA login credentials, which I'm pretty damn sure will NOT be stored on every single random server you hack? The ability to answer arbitrary HTTP requests on a server is sufficient to get a publicly-trusted certificate from any number of CAs. You do not need the credentials for the CA they've been using. Just create a new account. Future extensions for the DNS CAA record[1] might be able to help against this if you keep your credentials away from your web server. [1]: https://datatracker.ietf.org/doc/html/draft-ietf-acme-caa https://datatracker.ietf.org/doc/html/draft-ietf-acme-caa
- wfunction 9y ago> The ability to answer arbitrary HTTP requests on a server is sufficient to get a publicly-trusted certificate from any number of CAs. I'm saying you have to know what response to GIVE, don't you? You can't just give a random response...
- problems 9y agoThe CA tells you what response to give on that new account you signed up.
- wfunction 9y agoThanks, that didn't occur to me since I was mostly thinking of EV certs for some reason.
- pfg 9y agoThere's nothing to stop you from creating a new account at the CA of your choice, asking for a validation token, and putting it wherever it needs to be.