17 ms·
OK, so in your example they create a certificate and use HTTPS and I'm unsure what the problem is. And why would they think outside of their internet only box
by quotheth 9y ago
OK, so in your example they create a certificate and use HTTPS and I'm unsure what the problem is.
And why would they think outside of their internet only box when they're providing an internet browser?
- tokenizerrr 9y agoIt's impossible to get a valid SSL certificate for an appliance running within someone their lan, without having to open ports. And opening ports would make the appliance even more vulnerable to attack.
- quotheth 9y ago> It's impossible to get a valid SSL certificate for an appliance running within someone their lan Can you not just create a certificate and push it to the system as a trusted cert? > And opening ports would make the appliance even more vulnerable to attack. Presumably there is already some sort of communication going on if they're receiving Chrome updates.
- tokenizerrr 9y ago> Can you not just create a certificate and push it to the system as a trusted cert? If you were to control the user's machine, yes. But imagine you bought a shiny new internet connected coffee pot. Once you turn it on it does the following: 1. Coffeepot Determines its LAN IP address (e.g. 192.168.1.100) 2. Coffeepot connects to the coffeepot cloud service to register a dynamic DNS entry (e.g. user1.coffeepot.com) to point to its LAN IP address. 3. User is told they can access their coffeepot WebUI by going to user1.coffeepot.com, which resolves to 192.168.1.100 This is secure since the coffeepot can only be controlled if you are in the same network. Yet, since the coffeepot webui can only be reached if you are in its network, it is nearly impossible to get a valid SSL certificate on the coffeepot appliance. > Presumably there is already some sort of communication going on if they're receiving Chrome updates. There is a difference between outgoing network traffic and incoming network traffic. Only the latter requires open ports.
- WorldMaker 9y ago2.alternative: Coffeepot connects to the coffeepot cloud service to register a dynamic DNS entry (e.g. user1.coffeepot.com) to point to its LAN IP address and sends a Certificate Signing Request for user1.coffeepot.com? If you are already registering a dynamic DNS, a CSR shouldn't be that much additional overhead?
- tokenizerrr 9y agoActually, now that I think about it, with the Let's Encrypt DNS challenge this might actually be viable... That's pretty recent, though. And they rate limit harshly. I was thinking about the HTTP validation, which would definitely fail, due to the DNS resolving to a LAN IP. Which a CA would obviously not be able to verify.
- WorldMaker 9y agoRight, that burden becomes coffeepot.com's. Supposedly they would already be doing due diligence to make sure that the dynamic DNS requests were from legitimate coffeepots that they themselves manufactured (rather than say the fraudulent activities of a botnet using their open DNS for communications). At that point they should also have enough security information to verify if they should sign a certificate presented to them by their manufactured coffeepot under their certificate authority delegation to *.coffeepot.com. To my knowledge you can even piggy back off of ACME's protocol work from Let's Encrypt, even if the auth/validation checks are different for the different security models.
- tokenizerrr 9y ago> under their certificate authority delegation to *.coffeepot.com. Where can I get a certificate with the CA flag set for mydomain.com? I did not know this was an option for mere mortals.
- WorldMaker 9y ago
- Ajedi32 9y agoIt's definitely not impossible. Plex does it automatically: https://blog.filippo.io/how-plex-is-doing-https-for-all-its-users/ https://blog.filippo.io/how-plex-is-doing-https-for-all-its-... Now that fully automated certificate issuance is becoming more mainstream (thanks to Let's Encrypt) I foresee this sort of thing becoming much more common in the future.
- tokenizerrr 9y agoUnless I'm misunderstanding they did that by partnering with a CA. Becoming a semi-trusted CA themselves. This is not an option for most organizations.
- Ajedi32 9y agoThat was only necessary because, at the time, there was no other way to get a large number of wildcard certs issued for their domain in an automated fashion. With ACME that will no longer be the case. Let's Encrypt will allow you to do basically the same thing for free with ~20 devices a week[1] starting on February 27[2], for example. In the future, commercial CAs may choose to offer similar services with more relaxed rate limits. [1]: https://letsencrypt.org/docs/rate-limits/ https://letsencrypt.org/docs/rate-limits/ [2]: https://letsencrypt.org/2017/07/06/wildcard-certificates-coming-jan-2018.html https://letsencrypt.org/2017/07/06/wildcard-certificates-com...
- tokenizerrr 9y agoYeah, would be nice if ACME with DNS validation was widespread. But right now it's still not viable due to Let's Encrypt's rate limits.
- pfg 9y agoIt's fairly trivial to request a rate limit adjustment from Let's Encrypt[1]. [1]: https://docs.google.com/forms/d/e/1FAIpQLSetFLqcyPrnnrom2Kw802ZjukDVex67dOM2g4O8jEbfWFs3dA/viewform https://docs.google.com/forms/d/e/1FAIpQLSetFLqcyPrnnrom2Kw8...
- deleted 9y ago[deleted]
- fulafel 9y agoIt's possible, why not? Just use your own servers as a cert signing service for your IoT device as part of the bootstrap process if you are unwilling to have any services running on it. Or ship the device with the signed cert. You can have the host name in the DNS even though it's not accessible from everywhere.
- Zarel 9y ago> Or ship the device with the signed cert. Certs expire sometimes. And the device doesn't necessarily have an internet connection. What then?
- deleted 9y ago[deleted]