3 ms·
Yes, the last sentence was meant to be a tautology — the trusted CAs are trusted, if a trusted element is hosed, you are hosed, that's what trusted means. I hav
by Robin_Message 16y ago
Yes, the last sentence was meant to be a tautology — the trusted CAs are trusted, if a trusted element is hosed, you are hosed, that's what trusted means. I have no doubt you are more knowledgeable and experienced in this than me, and of course you're right that you can remove the Chinese CA, but I don't think that is a sufficient solution to the proposed attack.
Firstly, I doubt that US (say) government personnel will remove Chinese CAs, never mind contractors or even ordinary business people or citizens, so to my mind this is a risk to trusting SSL, even if expert users can mitigate it as you have described.
Secondly, I believe CAs can also sign other CAs (and indeed Entrust did this for this very Chinese CA) so it's not that simple. You might need to distrust most CAs, which makes using SSL slightly tricky.
Thirdly, even if you remove the CA now, how do you know you weren't already MITM-attacked back in February? It's too late.
As for mitigation, alerting the user on CA or certificate changes might help, but getting the UX right will be hard. I could see a solution in the future where your bank sends you a memory stick with portable firefox installed on it and precisely one trusted certificate — the bank's. Of course, that means trusting the mail system, but since we already trust the mail system (e.g. using mailed statements for ID verification) we can't be worse off. An attack would require hijacking the USB stick and your connection to the bank at the beginning of the same session for it not to be noticeable — not so easy.