19 ms·
How not to run a CA
- herodotus 9y agoletsencrypt is great and I use it. But I don't really get it. All I needed to do was prove that I could place a generated file on the server that I wanted the certificate for. This seems to me to be a very low bar. What am I missing?
- codebeaker 9y agoThey're not verifying your identity, just that you control the hardware running the domain that you want to generate a certificate for.
- peterwwillis 9y agoCorrection: that you can control the IP space advertised to Let's Encrypt. A BGP exploit would result in getting valid certs for someone else's domain/host. It's almost trivial to exploit BGP, which is why PKI is so important... so it should actually be incredibly difficult to get a cert.
- discreditable 9y agoIf someone is hijacking BGP to MITM the world, how are the old methods any better?
- snuxoll 9y agoIf you could hijack BGP you could just as easily inject routes to intercept DNS requests as well.
- vsund 9y agoThere's a difference in certificate type. Let's encrypt (which only issues basic certificates) just verifies that you're the rightful owner of a domain, not whether the domain is what it says. If you'd like to have more verification for your certificate you need a extended validation certificate (which often costs money). These certificates also include your (company) name and the issuer verifies whether it's correct or not. Basic certificate issuers don't judge over domain names or content, they just verify domain ownership.
- pfg 9y agoTo clarify, other certificate types do not judge content either. The difference is that they verify your organisational details (to a varying degree, depending on the validation level) and include them in the certificate. The CA is not going to check whether the business is fraudulent or anything like that.
- walrus01 9y agoTo clarify for people who've never bought one, an EV SSL cert actually involves work by humans at the CA. They do things like obtain copies of your state/provincial corporate registration, business license, LLC registration, local business license, etc. Then the do basic matching that your physical business address of record matches with what your state's Secretary of State has on file for your corporation. It's about a half hour process on the part of the CA of verifying the existence of a real business entity.
- Diederich 9y agoThe bar for basic certs has been, for some time, an indication of control over the DNS domain in question. In the past, the bar used to be much higher. Whether a lower bar is a good idea or not I will leave to other more informed folk.
- cortesoft 9y agoWhen was it higher, and what made it higher? The only extra thing that you used to have to do is pay money....
- jnbiche 9y agoThey're not verifying your identity since it's a domain validated cert. The point is just to ensure that communications between a user's browsers an www.somerandomdomain.com are secure, regardless of who is behind the domain in question. For identify validation, you'd need to buy an EV or OV cert. But for most organizations, particularly if your domain IS your identity, a domain-validated cert is absolutely fine.
- walrus01 9y agoThat is basically the bar for a "DV" (domain validated) SSL cert. Let's say you are the owner of the domain rupertsdildoemporium.com and want to get an SSL cert. Since you own the domain you control the entries for what nameservers it uses. Since you control the nameservers, you can point the A record for the domain anywhere of your choosing. Or put an arbitrary TXT record in the DNS zonefile. That is the full extent of what you need to prove to get a domain validated SSL cert. It is complete and total bullshit that DV SSL certs still cost money (thanks LetsEncrypt), anywhere from $9/year to $80/year. The companies that rely on selling DV validated SSL certs for their business model are polishing the brass doorknobs on the Titanic. It's all going down. Just a question of when.
- thriftwy 9y agoI think we should use ssh instead of SSL and also ssh instead of username/password pairs. If somebody is doing a distributed chat/social system, I would use ssh if I were them. By ssh I don't mean execution commands but rather encryption/authentication framework.
- TheDong 9y agossh is, by default, Trust on First Use which is a significantly different model than a Trusted Thirdparty (CAs). There are some well known trade-offs, namely that having everyone manually verify fingerprints on initial connect and again on any server change is a large burden. I don't particularly want to have to go into my bank's local office and verify in person the fingerprint is correct each time they need to rotate a secret. If this isn't what you meant, that we should use TOFU vs Trusted third party, please do expand.
- thriftwy 9y agoI think it works much better for contacts. You have to verify contact once and then you are assured that it's still the same person.
- teraflop 9y ago> You have to verify contact once Only if users never replace their keys, which puts them at significant risk in the event of a key compromise.
- StavrosK 9y agoMirror, because the site wasn't loading for me earlier: https://www.eternum.io/ipfs/QmSjZic3JCaU3MHro8MyvRi1RpQweuYCen2HGpyFUTauWX/ https://www.eternum.io/ipfs/QmSjZic3JCaU3MHro8MyvRi1RpQweuYC...
- deleted 9y ago[deleted]
- peterwwillis 9y ago> TL;DR: Forget your EV or other certs. Just run “Let’s Encrypt”. It gets you a cert, it’s fresh, and it does not make any difference whatsoever. At least not any you or anyone else can check for, or cares for. Let's Encrypt shut down their new test interface because of a security flaw they found. If this was in a production service, this would have been about as bad of a security flaw as is possible in a PKI system. Let's not get all high and mighty assuming Let's Encrypt won't get compromised; they probably will. We should be planning for how to deal with that.
- majewsky 9y agoThat doesn't make sense. You cannot criticize someone for finding an issue in the testing environment before it hits production. That's literally what the testing environment is for.
- peterwwillis 9y agoI was not criticizing them (can you quote the part of my comment that was critical?). I was illustrating that they are not perfect, and just using them without considering that they too could be compromised is a bad idea.
- aidenn0 9y agoAt least with LE we're not paying to have our data compromised :)
- nailer 9y agoOriginal (and much more accurate) source: https://www.digicert.com/blog/digicert-statement-trustico-certificate-revocation/ https://www.digicert.com/blog/digicert-statement-trustico-ce... HN discussion: https://news.ycombinator.com/item?id=16485801 https://news.ycombinator.com/item?id=16485801
- nailer 9y ago> TL;DR: Forget your EV or other certs. Just run “Let’s Encrypt”. The author has a fundamental misunderstanding of the situation [1]. Trustico's awful decisions regarding a) storing customers private keys and b) improperly handling key material Have no bearing whatsoever on EV certs, which verify the legal entities that run websites. This is like saying Trustico is bad, therefore HTTPS is bad. [1] Assuming this is what the author said - the site is in plain HTTP so integrity isn't guaranteed.
- rkangel 9y agoThere is at least some merit to the argument that "Trustico Bad" => "CAs bad" => "HTTPS Bad". More than one CA has been shown to be extremely lacking in trustworthiness and that trust is important. I'm OK with the centralised model but there needs to be a bit more visibility of the CA process.
- Karunamon 9y agoI'd settle for an end to the credentialism that ensures only the rich and powerful can enter the CA business. The actual technical chops and physical/operational requirements to become a CA are modest by the standards of the average HN reader, but the financial cost for the audit required to wind up in the browser trust stores is prohibitively high. ...That, and given the massive failures we've seen coming out of the CA world recently, I question whether those audits are actually worth anything.
- cortesoft 9y agoAren't the audits what allow us to find out about the failures, and revoke their ability to be a CA?
- Karunamon 9y agoHow many of the most recent failures have come to light as a result of a failed audit, and how many were due to a post-audit, outrage-generating violation of basic best practice and common sense?
- mkhalil 9y agoIn related news, Trustico's site is down apparently due to users being able to run commands as root on their webserver. I wonder if this was used to extract some private keys? https://twitter.com/svblxyz/status/969220402768736258 https://twitter.com/svblxyz/status/969220402768736258 https://twitter.com/Manawyrm/status/969230542578348033 https://twitter.com/Manawyrm/status/969230542578348033
- tetha 9y agoI am aware this is not contributing to the thread but... the only way I can summarize my feelings on that is 'holy fuck'. I just spent a minute just muttering 'holy fuck' to myself. They are running the good old php shell of "<%= system(%_REQUEST['cmd']) %>". As root. As a security company. This entire company is just blowing my mind at the moment. What's next, are they running their services on a notebook in the office?
- acobster 9y ago> mailed 23000 private keys I had a similar thought. My thought was: "HOLY SHIT!"
- blattimwind 9y ago"As a security company." Well, their CEO's linked-in profile doesn't really sound like a security company. > Email Marketing Digital Marketing Google Analytics Google Webmaster Tools Market Analysis Marketing PPC SEM SEO Sales Security Social Media Marketing Web Analytics Affiliate Marketing Google Adwords Management E-commerce Lead Generation Online Marketing Online Advertising SaaS Marketing Strategy Strategic Partnerships Cloud Computing New Business Development Business Strategy Start-ups Web Development CRM Social Media Product Marketing Solution Selling Strategy Channel Partners Channel Sales Business Alliances Business Development Leadership Social Networking Network Security Hardware Product Management B2B Professional Services GTM Partner Program Development Internet Security Google B2B Marketing Sales Operations
- tetha 9y ago
- firloop 9y agoThe thing that isn’t clear to me is how Trustico even had the private keys to begin with. It’s been a while since I’ve purchased a SSL certificate, but I remember generating the private key locally and providing a certificate signing request, which isn’t the private key. What am I misunderstanding here?
- KMag 9y agoYou remember correctly the way things should happen. But, presumably, Trustco generated the public and private keys for the customers, signed the certificates, and handed the whole mess to the customers. I imagine some customers would even pay a bit more to not have to bother learning to generate a keypair and signing request themselves. The thing I don't understand is how the CEO thought things would likely work out to his advantage. He must have realized that the person holding all of the cards didn't want to cooperate, and decided to try and bully that person into acting against Trustco's customers. To make such a colossal misjudgement makes me curious what else this CEO has done at previous companies.
- ChrisSD 9y agoIt sounds like Trustico got these certificates from Symantec. The CEO of Trustico was arguing that they should be revoked as they weren't secure and emailed the private keys as proof. Which, while a dumb thing to do, did prove his point I guess. EDIT: From Trustico's account > We believe the orders placed via our Symantec account were at risk and were poorly managed. We have been questioning Symantec without response as to concerning items for about a year. Symantec simply ignored our concerns and appeared to bury them under the next issue that arose... We were also a victim whereby Symantec mis-issued SSL Certificates owned by us, subsequently we were asked to keep the matter quiet, under a confidentially notice. https://groups.google.com/d/msg/mozilla.dev.security.policy/wxX4Yv0E3Mk/jx6r9jlPAwAJ https://groups.google.com/d/msg/mozilla.dev.security.policy/...
- Ajedi32 9y agoWhy would they not try to transition their customers to new certs _before_ getting all the old certs revoked though? Seems like suddenly revoking 23k of their customer's certs with only 24 hours notice is just shooting themselves in the foot.
- cup-of-tea 9y agoSSL is fundamentally broken. Web-of-trust is the only real way to do security.
- Spooky23 9y agoThe only thing I trust less than a CA is an army of Russian troll bots.
- RKearney 9y agoYes, SSL has been broken for some time. That's why TLS was introduced nearly 20 years ago.
- dpark 9y agoYou presumably got downvoted for being pedantic here, but I think your pedantry is reasonable. If someone's going say "X is fundamentally broken", they should know what X is actually called. Referring to TLS as SSL reeks of amateur hour and shallow knowledge[1], and is a mistake on par with referring to Javascript as Java. [1] This is the sort of lazy mistake I would make, because I'm not a security expert.
- cup-of-tea 9y agoThe first line of the blog post calls it SSL. It's irrelevant to what I said because I'm talking about the public key infrastructure.
- dpark 9y agoThe blog author is also not a security expert. And I understand that your real criticism was with PKI. That makes it even worse that you called it SSL. Again, I feel like you're showing your lack of expertise in this area. I'm not an expert at all in this area and yet even I can recognize that you're playing armchair security expert.
- peterwwillis 9y ago
- empath75 9y agoOh, it's worse than that: https://twitter.com/svblxyz/status/969220402768736258 https://twitter.com/svblxyz/status/969220402768736258 You can run arbitrary shell commands as root from their webserver.
- dx034 9y agoI guess someone started playing around, their server now responds with a 503.
- deleted 9y ago[deleted]
- warent 9y agoCue the intro to Bohemian Rhapsody. This is a huge WTF. SQL injection? Too basic. We do raw shell injection now. To a CA. Welcome to the future of computers where security comes secondary to extra profits and marketing.
- Ajedi32 9y agoFWIW, Trustico isn't a CA. They're a certificate reseller; all certificate validation is handled by a different company. If Trustico hadn't been generating their customers private keys for them (or if their customers had refused to let them do things that way) they wouldn't have been able to screw things up this badly.
- warent 9y agoGot it, that kind of makes sense. The concept of certificate reseller doesn't make a whole lot of sense to me but thank you for making the distinction
- tialaramex 9y agoMostly they exist because of price discrimination. Rich Uncle Bob hears he needs an "SSL Certificate" he's heard of "Thawte" brand SSL, he goes to the brand website and clicks "Buy $69.99 per year". His savvy friend Tight Mike needs one too, he shops around, finds a reseller called "Discount SSL" that offers an Thawte certificate for $18.99 What's the difference? Nothing except that Tight Mike was looking for a cheaper price, and if "Discount SSL" didn't sell it to him for $18.99 he might have eventually kept looking enough to find that somewhere else has a GoDaddy cert for $12.99 or whatever. Bob didn't care, he just paid whatever they asked, so wring the maximum possible out of him. In theory there's also some more traditional "sales and service" type role, where they educate customers, help manage local experience e.g. maybe the Reseller is in Egypt and your English isn't so good - and that sort of thing. But a LOT of the business is straight price discrimination, trying to ensure as much of the customer's money goes to you as possible without them switching to a competitor with lower prices.
- sphix0r 9y agoIronically his blog isn't available on https. Would be time that browers mark http sites' address bar as "Not secure" in orange. It's either secure or it isn't. Fun fact; Europe's ePrivacy law is coming next year which enforces all communication to be secure.
- sigzero 9y agoWhich they cannot enforce on the web except by blocking (aka censoring the web).
- photonios 9y agoThey could fine you.
- kcolford 9y agoOnly if you are (or will be) incorporated in the EU, which generally you should be in order to accept payments from and do business in the EU.
- kerkeslager 9y agoI live in the US, operate in the US, and if I ever go to the EU, I am quite confident that the system won't move quickly enough to notice I'm in the EU and collect fines during a tourist stay. So no, they couldn't fine me. If they did fine me, there would be zero repercussions for simply ignoring the fine. I am not saying I plan to break this law: I'm a big supporter of encrypting everything and I was in compliance with this law before this law existed. I think that this law is a big positive step for privacy in the EU. I am saying that the claims that this EU law will have massive international effects are overblown. There are five other continents with major businesses and only the businesses which operate in the EU have any reason to care about EU laws which are enforceable only in the EU. EDIT: I accidentally a continent.
- _jal 9y agoRight, because the only way we can control speeding is by barricading roads.
- kasperni 9y agoThey have a tool that allows you create a private key + CSR https://www.trustico.com/ssltools/create/csr-pem/create-a-new-csr-instantly.php https://www.trustico.com/ssltools/create/csr-pem/create-a-ne... Apparently they decided to keep a copy of the private key. Edit: Looks like they are having problems atm. A copy can be found at https://web.archive.org/web/20180217071027/https://www.trustico.com/ssltools/create/csr-pem/create-a-new-csr-instantly.php https://web.archive.org/web/20180217071027/https://www.trust...
- dx034 9y agoThis probably happened because they allowed users to execute root commands on their server. Either they quickly shut down the site or someone else did it by shutting down some servers. > https://twitter.com/svblxyz/status/969220402768736258 https://twitter.com/svblxyz/status/969220402768736258
- jiggliemon 9y agoOh my. There must be some sort of hall of fame for security vulnerabilities. And this belongs in it. Perhaps they’re passing this command to a secured container? I shouldn’t make excuses for them, but passing root commands to the shell seems too far out there.
- zbentley 9y ago> root commands to the shell seems too far out there You haven't been in software too long, have ya? /s Glibness aside (and I meant the above as a joke, not a personal attack), this is distressingly common to the point of being near-universal in some areas of our industry.
- profmonocle 9y ago> Perhaps they’re passing this command to a secured container? That would indicate they were concerned about shell injection while writing the code. But if that were true, why would they skip the much simpler step of sanitizing/escaping the input?
- 9y ago
- devit 9y agoBrowsers need to remove all CAs except Let's Encrypt. CAs have proven again and again to be ridiculously insecure, and the problem is that there is no penalty for their mistakes. So just remove them all, after a warning period: Let's Encrypt is enough. Or if they want to stay in business and be trusted by browsers, then require them to put up at least $100k in cash in escrow for each certificate they sign, which is forfeit if there's evidence that any compromise of that specific certificate, due to their fault, has or may have happened, with at least half of the money being distributed to whoever provides the evidence first.
- kbsletten 9y agoI'm not sure that's as good an idea as you think. Even LE has designed ACME to ideally be replicated elsewhere. The big problem with having only one CA is that if they get compromised or go down, that's the entire internet. For good reason, it's not like you can launch a CA in a day, so we will always need a few horses in this race. Culling the herd isn't a bad idea, but without some diversity any issue could be catastrophic.
- anonymfus 9y ago>The big problem with having only one CA is that if they get compromised or go down, that's the entire internet. Compromising any CA affects the entire internet.
- Dayshine 9y agoYeah, Let's Encrypt doesn't support OV or EV certs...
- devit 9y agoThe simple solution is to always require a certificate by Let's Encrypt, and allow the website to optionally present a second OV/EV certificate in addition to the Let's Encrypt DV certificate. Although it's unlikely that's of any use, since unsophisticated users aren't going to differentiate, and sophisticated ones can use other means to verify identity.
- zokier 9y ago> proving that Trustico has knowledge of all their customers private keys, keeping copies of them, which proves that they never knew how to run a Certficate Authority business in the first place Well, they also weren't actually running a CA business either.
- syncsynchalt 9y agoWhile the article title is accurate (you should not run your CA in this manner), Trustico is not a CA but is instead a reseller of CA services.
- originalsimba 9y ago"Bad Actors" in the tech field tend to flock together. Comodo has been at the center of several really ugly stories, this one being the latest. The CEO of Comodo attempted to sue Lets Encrypt before they launched, in order to kill the project because of the threat it represented to their business model. after 24 hours of backlash from the internet public he backed down and said it was all a misunderstanding. Of course. Cloudflare uses Comodo for their SSL. They could use some other cert authority, but they chose to use Comodo. This is on topic, in a general sense of CAs and trust. It bears repeating: Bad actors tend to flock together.
- sneak 9y agoYour argument for guilt by association is not compelling. Cloudflare is their customer. I am Cloudflare’s customer. Does that make me a bad actor too?
- deleted 9y ago[deleted]
- Bombthecat 9y agoThe question is: why does cloadflrare even use them? There are like ten thousand other options...
- PuffinBlue 9y agoI believe at the time they deployed their Universal SSL, which was over four years ago, is absolutely massive scale, and is free, they were the partner that could actually deliver the necessary integration and infrastructure to handle that sort of load. Also, they were amongst the only ones to offer ECDSA certificates IIRC. Cloudflare detailed a little bit about this in this and other blog posts: https://blog.cloudflare.com/universal-ssl-how-it-scales/ https://blog.cloudflare.com/universal-ssl-how-it-scales/
- prdonahue 9y agoWe use several CAs to issue—Comodo, DigiCert, GlobalSign—and will be adding Let's Encrypt once they support i) SHA-2/ECDSA signatures and ii) wildcards. Having multiple issuers is important for us as each CA, at some point in time, has operational issues. Additionally, as you've seen with Symantec, browsers take action to distrust certain issuers/roots. When either of these scenarios happens, our customers don't care if it's the third-party that's down—they expect fast and reliable issuance from us (Cloudflare).
- deleted 9y ago[deleted]
- makecheck 9y agoThis shows that you need a lot more than a fancy web site to convince you that a CA is professional. It’s kind of crazy how little we know about these important institutions. Credit reporting agencies are another example of complete incompetence in a presumed-sensible organization. Especially once money changes hands, there ought to be a lot more terms in the contract to specify good behavior. You need backup when you discover something is run by 6-year-olds.
- pas 9y agoThis was a "reseller", and they don't have to be audited, and the browser CA inclusion policy probably doesn't mandate anything from CAs regarding their resellers. Well, it should.
- shatteredvisage 9y agoWhat a dumb usage of an acronym. You really couldn't put Certificate Authority in the title? CA means so many things it's laughable. Is this meta clickbait?
- walrus01 9y agoThis is such a clusterfuck I don't even know where to begin. I am very happy that "pay money" for DV SSL certs is going the way of the dinosaur, with Let's Encrypt. The only SSL cert you should ever pay money for is $90/year for an EV SSL cert for an ecommerce/product purchasing website where people are entering credit card details. The big friendly green bar GUI element, for non-technical users, is worth it.
- 0XAFFE 9y agoI would pay for an acme endpoint that is not rate limited.
- techmonster 9y agoYou don't have to pay; you just have to ask. :-) https://letsencrypt.org/docs/rate-limits/#overrides https://letsencrypt.org/docs/rate-limits/#overrides
- fredsted 9y agoAnd it just "takes a few weeks"!
- giobox 9y ago> I am very happy that "pay money" for DV SSL certs is going the way of the dinosaur, with Let's Encrypt. > The only SSL cert you should ever pay money for... You can still "pay" Lets Encrypt, my understanding is that as a non-profit they rely primarily on sponsorship and donations. If you are using them in production for a product making money one could at least consider throwing them a donation. If no one contributes we don't get to have nice things like LetsEncrypt!
- ahmedalsudani 9y agoThis is going to be the funniest thing I read all day. Thanks for writing it up!!
- shruubi 9y ago> So the CEO of Trustico, Zane Lucas, mailed the private keys of 23000 Trustico customers to Digicert How is it that these guys have managed to stay in business for this long?
- johnhenry 9y agoI'm wondering if anyone could explain what the "right" thing for Trustico to do?
- Ajedi32 9y agoThey should not have offered a web form for generating private keys, and instead should have educated their customers on how to generate their private keys and CSRs on their own servers. If they had done that they wouldn't have had access to any private keys in the first place, so all their subsequent mistakes in mishandling those keys would have been impossible to make. As for the whole "arbitrary Remote Code Execution as root" on their web server, that's got a pretty obvious solution: sanitize your data inputs, and don't run your web application server as root.
- benmmurphy 9y agoalso, 23,000 people disclosed their private key to a third party. a) in a sense maybe they thought they were disclosing their private key to a their CA so in a sense it didn't really matter because their CA could issue certificates for their domain anyway (... ignoring certificate transparency/other external verification) [... we know this is not true and it's mostly people don't know/don't care/it doesn't matter what they are doing in the scheme of things]
- kerkeslager 9y agoIntel is breathing a sigh of relief that finally there's a distraction from Spectre and Meltdown.