4 ms·
The box controls the DNS; majorwebsite.com points to any sever the attacker likes. The only defense is HSTS/certificate-pinning, for sites previously visited w
by confounded 8y ago
The box controls the DNS; majorwebsite.com points to any sever the attacker likes.
The only defense is HSTS/certificate-pinning, for sites previously visited with that browser & device (it’s a TOFU security model).
HN has HSTS, but not Reddit, or my credit union, or my local pizza place, or Kaiser Permanente, etc. etc. etc.
EDIT: I believe e.g. Chrome and Firefox bake in some major certificates, which would also likely flag MITM attacks, for those sites.
EDIT II: Someone responded below (since deleted) that you’d also need that cert to be signed by a CA your browser trusts, which is true. My explanation is faulty/poor. Better informed discussion of attacks further down the thread!
- deleted 8y ago[deleted]
- kupiakos 8y agoThat's assuming the box can generate certificates trusted by the target machines - there's a reason the CN field exists.
- ardy42 8y ago> That's assuming the box can generate certificates trusted by the target machines - there's a reason the CN field exists. If you're dumb enough to install one of these boxes on your network, you might also be dumb enough to install an attacker-provided root certificate on your PC.
- VMG 8y agoBut if you ask your user to install a CA, why not simply ask him to install malware? Is it to circumvent antivirus?
- tialaramex 8y agoThe X.500 series Common Name is a weird thing to fixate on here. It's an arbitrary free text "name". The only reason it's even sometimes useful in the modern era is that the CAB BRs say it has to match one of the SANs so it will probably be a DNS name. But even there good luck, it took until 2016 or so to get the last stragglers to obey that rule properly without "misunderstanding" it and unlike SANs it isn't defined to be DNS A-labels so it may have arbitrary Unicode text. Most browsers stopped even looking at CN or only do so for people's crappy home grown private CAs Anyway, what makes certs trustworthy isn't the CN, it's a chain of two or more digital signatures leading to a trusted root. And the CN in that root, while it had to be truthful when written, may be twenty years old, so it's nonsense now.
- evilDagmar 8y agoGood luck finding anyone willing to issue you a cert that's valid for 20 years.
- tialaramex 8y agoLeaf certificates have a maximum permitted lifespan of 825 days (down from 36 months) But I wasn't talking about leaf certificates, I expressly mentioned this for the CN in _root_ certificates and it's pretty common for those to have a lifetime of ten, fifteen even twenty five years. Here's an easy to remember example, https://crt.sh/?id=1 https://crt.sh/?id=1 the first entry in the crt.sh database. The Common Name on that certificate is "AddTrust External CA Root". So... who are AddTrust? I actually have no idea. This root is today controlled by Comodo, a CA in the United Kingdom but you'd never guess that from the certificate.