4 ms·
As a non-techie, can someone expand the reddit post below, and why each individual's person private key is thought to be secured? Is the private key like a supe
by TaylorSwift 9y ago
As a non-techie, can someone expand the reddit post below, and why each individual's person private key is thought to be secured? Is the private key like a super password?
This is very concerning. The implication of this is super super dangerous. If anyone gets hold of the private key (which I sure hope is secure, but I'm not holding my breath), they can snoop on all of your traffic, and steal your password and credit card numbers. Usual Root CAs (Commodo, etc...) are held to very very very high standards in how securly they store their private key because of just how bad it is for it to leak. They are forced to undergo a very thorough audit process before being trusted. But since blizzard is not an official CA, they don't have to undergo the same process, even though a failure would be equally disastrous.
There is no valid reason whatsoever to install a Root CA here. What blizzard is doing is simply wrong, from a technical and ethical perspective. From what I understand, it is used to implement facebook login. There are other, better ways to do this. They could use an embedded browser instead of the default browser. They could use http instead of https (the url should be local anyway, and as such, secure). They could have registered a Custom URI scheme. The alternative, secure solutions are plenty.
Furthermore, Battle.net is failing in other ways. Everyone that has battle.net has a permanent server on localhost:22885. From what I gather, this is what they use to implement the facebook login, but the server is always on, instead of being only enabled when facebook login is actually in use. This is another big can of worm. We've seen previously that such things can lead to Remote Code Execution (basically a very convenient way to spread viruses) because any browser can make connections to it.
Blizzard needs to fix this shit now.
So far what I've done under my Windows 7 machine is to placed the certificate under "Untrusted Certificates" and under properties, turned on "Disable all purposes for this certificate". Are there any other measures that I should take to completely prevent this certificate from causing potential harm?
- Pyxl101 9y agoAccording to commits in this HN thread, including the one you're replying to (which I have not independently verified), that Reddit post is factually mistaken about crucial points. There is no reason to be alarmed, to worry about the certificate, or try to disable it. There may be some merit to the point about running the local permanent HTTPS server but that's unrelated to the certificate. I tried to expand this comment to include a technical explanation of the issues, but it became quite long. I'll try to simplify and summarize: there are legitimate security concerns about applications that install their own Certificate Authorities (CAs, aka root certificates), especially when the same one is being installed on all computers. A Certificate Authority has the ability to issue certificates for any website, so it has the ability to compromise the user's traffic to any website if mismanaged. Blizzard didn't do that. Blizzard installs a randomly generated, unique-to-the-user certificate (not certificate authority) for Blizzard's own website domain name. This does not present any of the security issues alleged by the Reddit comment. So there is no root certificate or CA involved -- the title of this HN article is incorrect and the Reddit thread is mistaken. (To caveat again: I have not personally verified this, and am digesting information supplied by other HNers) However, if you don't plan to log in to Battle.net using Facebook, then there's probably no downside to disabling this certificate either.
- TaylorSwift 9y agoThanks, so from my reading of this, this certificate had no functions of an actual root certificate and thus having MITM or other attack vectors aren't possible.