8 ms·
How is a gateway serving a configuration page at 192.168.1.1 to internal users supposed to eventually get an HTTPS certificate for that address...?
by wfunction 9y ago
How is a gateway serving a configuration page at 192.168.1.1 to internal users supposed to eventually get an HTTPS certificate for that address...?
- teddyh 9y agoEasy. Get a certificate for some name, say foo.example.com. Point foo.example.com, in your internal network's resolver, to 192.168.1.1. Use foo.example.com in the browser instead of 192.168.1.1. Done.
- wfunction 9y agoWho is supposed to do this exactly? Me the consumer who buys a router, or me the manufacturer of said router? (router/access point/whatever it's called...)
- gcp 9y agoThe manufacturer can set up a public DNS entry I think. i.e. it'd be config.linksys.com and that'd point to 192.168.1.1, but have a certificate that matches the one on the router.
- wfunction 9y agoOK, and (1) how are you supposed to trust that the manufacturer won't get hacked one day (or whatever) and the IP address won't change to something external/malicious? (2) what if I don't have an internet connection and don't have a DNS server on the gateway that can reply to such a query?
- lmm 9y ago1) If you trust them to write secure router firmware you can trust them to keep their HTTPS certificates safe - the former is a lot easer than the latter. 2) Router intercepts all DNS requests and responds with its own IP, responds to HTTP calls with HTTP 428, like already happens and like OSes already deal with appropriately.
- wfunction 9y ago> (1) If you trust them to write secure router firmware you can trust them to keep their HTTPS certificates safe wha? uhm, no. Just because I trust you to do something correctly once that doesn't mean I trust you to keep something else safe for all eternity. > 2) Router intercepts all DNS requests and responds with its own IP Actually, what if I have multiple of these routers in (say) a chain? I have to go physically find the one I need so I can connect an Ethernet cable to it and bypass all the others? I can't just connect to the one I want directly by its IP address?
- lmm 9y ago> Actually, what if I have multiple of these routers in (say) a chain? I have to go physically find the one I need so I can connect an Ethernet cable to it and bypass all the others? I can't just connect to the one I want directly by its IP address? Ah, I misunderstood, thought you were talking about a "captive portal"-type use case. If you're talking about having the router host some config interface like any other webserver then I'd say like any other webserver it should be able to generate its own certificate and CSR for a hostname you configure it with, and you submit that to your internal CA, or directly to let's encrypt or similar provider.
- wfunction 9y agoEr, what "internal CA" are you even talking about? Like imagine my grandma gets Comcast, her internet is not working, and I tell her to go to 10.0.0.1 to see if it shows anything. Suddenly she's supposed to get an HTTPS error warning her there's an MITM attack? Or am I supposed to tell her to install a root cert in her machine and every other machine she might connect in the future? Or heck, what if I'm just connecting to my damn scanner in my network? Or what if it's a guest trying to do that? "Sorry auntie, you'll have to install my self-signed cert as a root cert before you can use my scanner's web interface to scan your pic"?
- lmm 9y agoIf your router or scanner is to be accessible over the network then it needs its own name and it needs to be able to certify that that's its name. Anything else is just too dangerous. A user expects addresses they enter into the browser to mean the same thing on any connection; having a few "magic" addresses that go one place on one network and another place on another network is a recipe for users getting hacked. For the consumer use case, maybe the router gets a unique default address in the manufacturer's namespace (router12345.linksys.com) and ships with a certificate for that name and that name printed on the box, just like we do for the admin password. Since it's a router it's probably running the DNS for your network (at least in the consumer use case) so it can route requests for itself correctly. For scanners or similar, the router would need to update its DNS when the scanner joins the router's network - a lot of routers already do this within the local domain based on DHCP registrations, so this ought to be simple if it's not already done. Crucially this part isn't security-critical - if you try to print a confidential document on your network printer while you're on your neighbour's wifi, the worst their router can do is not route you, because an evil endpoint won't have your printer's certificate.
- gcp 9y agoCan't the router reply to the DNS request itself with 192.168.1.1? The public DNS record is needed to verify the DV cert, not to do the actual lookup.
- Merad 9y agoGreat, now what happens when I reconfigure my router to use 192.168.0.x IPs? Or 10.0.0.x? Or any of the millions of other possible options?
- gcp 9y agoIt's trivial to support the most common alternatives. Seems harder to add arbitrary support.
- pornel 9y agoAll CAs explicitly forbid manufacturers from doing so and will revoke all certificates used this way. This is because the device would have to ship with the private key.
- deathanatos 9y agoLet's pretend this is an ideal world; could ISPs just automatically assign DNS entries to their customer's IP address's? The router could figure out its public name via a reverse DNS lookup, then do a Let's Encrypt / ACME challenge for a certificate against that domain name. (I have no idea how the customer ends up knowing the domain name, though. Though, if ISPs are supposedly so eager to "differentiate" their product, hell, an easy-to-use interface to have full control over <yourname>.ISP.com would actually be a decent feature, but then, I don't know what would make non-hackers care about that.)
- lmm 9y agoIt's not. It's supposed to use a publicly routable address. Private addresses were an unfortunate hack that got massively overused when people would've been much better off putting the same effort into using IPv6.
- wfunction 9y agoHow is it supposed to get a publicly routable address when it's not necessarily connected to the internet?
- lmm 9y agoDelegate address space the whole way through your internal network - you should get a large enough block from your upstream ISP that this is fine. If you're too big for a single upstream ISP you should have your own AS number and participate in internet routing. If this is truly disconnected from the Internet then yeah HTTPS is unsuitable - it fundamentally relies on the idea that there's a central, universal definition for who owns "foo.com" so that users can rely on talking to the correct "foo.com".
- coding123 9y agoEvery router that ever existed will need to be able to connect to the internet before it is configured?
- AlexandrB 9y agoDown this path lies the IoT security apocalypse. Imagine every cheap, unupgradable IoT lightbulb with a publically routable IP address. If IPv6 was widely adopted tomorrow, I'd still run my home LAN services behind a NAT.
- lmm 9y agoAddressability != access. By all means firewall your devices (though I'd strongly recommend something more granular than a perimeter firewall - particularly in the days of insecure IoT devices, an attack could easily be coming from inside the network), but they can still have proper addresses.