5 ms·
What your saying doesn't really address the issue marcosdumay raised: That is, the issue with allowing this kind of introspection is its susceptibility for abus
by jake_the_third 9y ago
What your saying doesn't really address the issue marcosdumay raised: That is, the issue with allowing this kind of introspection is its susceptibility for abuse.
That said, your use-case of intercepting secure connections in your private network is a solved one: set up a private CA.
Wanting to weaken the security of TLS for everyone else for what amounts to your own convenience is very selfish.
- hueving 9y agoIs setting up a private CA even enough with certificate pinning?
- aaronmdjones 9y agoThe HTTP Public Key Pinning specification says that browsers should/may (I forget which) ignore the pin if the chain ends up at a private locally-installed CA, for this very reason.
- aaronmdjones 9y agoIt's also worth mentioning that an MITM proxy with a private CA root certificate could just strip HPKP headers out of any webpage it sends you. If your computer is tied to its network (e.g. corporate PC) it will never see it, so there's no issue.
- deleted 9y ago[deleted]
- throwaway613834 9y agoI'm confused, isn't this the normal criterion for a certificate being valid? If your certificate chain doesn't end in a locally-installed trusted CA then how is that any different from a random cert signed by a nobody off the street?
- tscs37 9y agoThere is a difference between a local CA and a CA part of the root store and/or as part of the system's CA bundle.
- throwaway613834 9y agoSo terminating in a root CA imposes more restrictions than terminating in a non-root CA here? Something about that seems off...
- tscs37 9y agoNot root CA. Root store. A root CA that has been installed by the computer administrator is assumed to be more trustworthy than the one installed by your OS.
- aaronmdjones 9y agoAs tscs37 explained, there's a difference between the CAs that came with your OS/browser by default, and ones you have installed. Pins are usually ignored if the chain ends at the latter, because that's exactly the sort of scenario that would be used for corporate TLS MITM.
- snuxoll 9y agoYou should have a private CA setup if you're doing TLS inspection, I have one at home deployed through group policy/apple configurator profile to filter web traffic on any system my daughter is logged into (she's five and plays games on pbskids.org and such, need to make sure she can't even accidentally get at inappropriate content if I step away for a couple minutes to get lunch prepared or something). Unfortunately (?) some companies are actively working against IT administrators (and in my case, parents) ability to inspect TLS traffic on their networks - Google being a big one with the recent release of Android Nougat requiring apps to opt-in to allowing user/admin installed CA's to be honored. User privacy is important, but if you're using a company-issued phone or allow their MDM to deploy a CA to the trust store on your own phone you should know what you are signing up for. Google Chrome pins the certificates for google-owned sites as well, so even if your private CA is installed in the system trust store it will flat out refuse to load google.com, etc.
- mixmastamyk 9y agoRe kids, might it be easier to whitelist sites instead?
- snuxoll 9y agoMakes it harder for my wife to introduce her to new things, if I used a whitelist she would have to pester me any time she wants to get her onto a new site and then there’s the PITA of dealing with CDN’s and other third party sources that can change on a whim. Whitelist would be safer, but it’s not worth the headache - we use blacklisting to try and prevent accidents for brief periods when we can’t supervise her access instead of falsely thinking it eliminates the need for supervision entirely. Regardless, still need TLS inspection either way - even pbskids.org is served over HTTPS these days.
- semi-extrinsic 9y agoCould you make a whitelist that, when faced with a site not on the whitelist, serves up a webpage that asks for the parent to enter a passphrase to add this site to the whitelist? Sounds like it could be a worthy venture. Make this software running on dd-wrt or whatever, then sell people wifi-routers with this preloaded so that they can just plug it to their existing routers with ethernet, and voila they have a kid-friendly separate wifi.