13 ms·
Spying on HTTPS
- 2T1Qka0rEiPr 7y agoVery interesting article, although if the message displayed to the end-user really was left at "You are using an unsupported environment variable: SSLKEYLOGFILE..." that would be truly awful UX with some potentially disastrous consequences.
- Ajedi32 7y agoWhy? What "disastrous" consequences are you envisioning from a message like that? Note that the rest of the message (the part you omitted) explains in plain English what the part you quoted means to the average user.
- 2T1Qka0rEiPr 7y agoSomeone gets nefariously MITM'd and instead of giving the user an informative message, they're presented with something which means nothing to the lay-person.
- Ajedi32 7y agoBut as I said, the rest of the text on that bar clearly explains what the message means, in terms a layman can easily understand. Is there anything lost by _also_ including the technical information necessary to diagnose the problem?
- 2T1Qka0rEiPr 7y agoYou mean "stability and security will suffer"? Sorry I didn't exclude it to try to make my point more convincingly, I just missed it altogether. Assuming that's the part you meant, do you really think that is sufficient in explaining the situation to the user. I'm very unconvinced, my parents would have no idea what that means and just close the warning.
- Epokhe 7y agoWell, your(and my) parents would download an .exe file to play Farmville and run it with admin privileges by clicking yes on the user account control popup. So, maybe a web browser is not the safest place for parents...
- Ajedi32 7y agoCan the warning be closed? My assumption was that it's persistent. I agree the warning isn't as specific or actionable as perhaps it would be ideally, but seeing as the browser has no idea why the SSL keys are being logged (it could just be for debugging purposes) or how to fix it without breaking things further, I'm not sure what more it could say.
- 2T1Qka0rEiPr 7y agoYeh, I acknowledge it's a difficult problem to solve, but I think if you have messaging at all, it should probably be a lot clearer, and link to some kind of article explaining the situation (which could cover the legitimate use cases such as anti-virus usage etc.)
- exabrial 7y agoI said awhile back that QUIC leaving out having a "non-s" mode was going to mean people would just leave keys dumping on :(
- Spivak 7y agoWhich is the desired result, right? Key escrow forces you to be explicit about who you're allowing to decrypt your traffic rather than letting it be everyone by default.
- userbinator 7y agoThere are many problems with using a MITM proxy, however. The primary problem is that it’s very very hard to ensure that it behaves exactly as the browser does and that it does not introduce security vulnerabilities. FUD. Why should we want "behaves exactly as the browser does", when browsers (in fact, mostly Google's) are in fact turning against their users? While browser vendors are wary of any sort of interception of HTTPS traffic Especially Google's, because that's one of the ways you can still block ads and modify pages to have them displayed as the user(-agent) wants, while it continues to slowly remove abilities from browser extensions. Similarly, the MITM might not support the most secure versions of protocols supported by the browser and the server (e.g. TLS/1.3) AFAIK there is no general protocol insecurity with TLS <= 1.2, unlike SSL3. There's also no reason for MITM proxies to not start using 1.3 too once it becomes more common, which I'm pretty sure will happen. this approach is generally preferable to MITM proxies. ...because it provides no way to modify the content, i.e. being able to do things like block ads, inject stylesheets, and generally behave as the user wants. IMHO the whole "security" thing has turned into a power-grab for companies to enforce their control over users, which is the most disturbing part. We want security, but also control, which is not the "security" they want. (This comment was posted from a browser that does not support even SSL 2.0, but is using TLS 1.2 via a proxy... and I know that 1.3 will be coming sometime in the future. When that happens, everything that goes through it can also start using 1.3.) Edit: yay, instant downvotes! I hope you enjoy being herded by Google, because that's where the future is heading if we don't oppose.
- jakub_g 7y agoI assume you've never heard of ISPs or vendors that _inject_ ads and other shenanigans on non-https and decrypted https websites?
- userbinator 7y agoThat's the ISP's problem. Mine doesn't do that. I trust it more than Google, at any rate.
- sascha_sl 7y ago
- egdod 7y ago> monster in the middle (MITM) That’s not what it stands for. There’s nothing sexist about using an acronym the same way everyone else does.
- Rudi9719 7y agoGender neutral and more accurate, it might not be how everyone else uses it but you got the meaning, no?
- rumanator 7y ago"Man in the middle" is not only an established concept it also is self-explanatory. Furthermore calling intercepters "monsters" is also a highly insensitive thing to do, if we're going to play the virtue signaling card. All this quixotism towards grammar and language is very stupid and pointless.
- jraph 7y ago> "Man in the middle" is not only an established concept it also is self-explanatory. Being comprehensible and established does not make it "good" (sure, this is a relative notion). I get your point of view about calling the interceptors "monster", but we are calling the whole process an "attack", this could already be considered a judgment call with this reasoning. Monster are not necessarily evil though. A myth that Monsters, Inc is actively trying to debunk :-) > All this quixotism towards grammar and language is very stupid and pointless. Many non-ignorant people think differently, so you need to argue here. Saying they are doing a stupid and pointless thing will not convince them.
- rumanator 7y agoYour attempt to force your personal blend of newspeak onto the world has no place in tech nor in this discussion. Please leave your gender politics activism out of an interesting technical discussion that affects us all. Besides being pointless and stupid, it only adds noise to the debate.
- Rudi9719 7y agoHonest question, is it possible to have chrome disable the functionality to export the SSL private key? IE on that notification is there a button to deny the stream?
- jackewiehose 7y agoWhy should they do that? This is a developer option that has to be explicitly turned on. If you don't want that, don't turn it on. I don't think normal software should need to take account of every way anti-viruses might abuse features.
- gempir 7y agoChrome isn't exporting the private key. It's importing the key you give it. Idk for what that is useful besides Virus Scanners, but personally I would like my browser to make its own key and never leak it or accept new ones.
- tialaramex 7y ago> Chrome isn't exporting the private key. It's importing the key you give it. No. It is _exporting_ the _secret_ key. It can't import the key, in many modern key agreement schemes neither client nor server gets to dictate the keys used, if you used a fixed or predictable value instead of a random one you just give up your security, you gain nothing. So the keys are (and should be) random for each session.
- tialaramex 7y agoWhat private key? Again, these are _secret_ keys. That's why the word SECRET n capital letters appears in that output at the end. Symmetric cryptography is used to actually transport data, and so it uses secret keys. These are agreed between client and server for each session and by getting a copy of them you can read (and in principle modify) the data as it passes between them. A private key would be a key that only one party knows. The notification is a reminder that this is an unsupported configuration of the browser software, useful for developers but not really intended for your garbage "Anti-virus" software to try to hook into. Just remove/ disable the AV?
- commandlinefan 7y agoLast I checked, Wireshark can't be configured to decrypt a TLS 1.3 session (at least not yet).
- drewg123 7y agoVersion 3.0.2 works fine to decrypt TLS 1.3 I'm using it right now, in fact, as I work on adding TLS 1.3 support to FreeBSD's kernel TLS
- tialaramex 7y agoTime to check again, Wireshark can consume TLS 1.3 keys from a client or server to decrypt the session using the environment variable described here. I'm not actually sure which version you need, maybe 2.6 or later?
- ignoramous 7y agoIs MITM, as described in this article, using sslkeylogfile possible on Chrome for Android?
- sagebird 7y agoListener in the middle is most accurate and Politically Correct.
- unethical_ban 7y agoI just want to state that some kind of clear-text inspection of content is and should be absolutely expected for security and DLP purposes in an enterprise environment. If TLS is going to become un-MITM-able, then we need to do it on the host.
- xg15 7y agoOk, dumb question. If apparently any kind of technique to intercept an HTTPS stream makes security experts frown, how are you actually supposed to inspect them if you have a legitimate reason? (e.g. monitoring unusual behavior of your own system) Or is the security best-practice to just trust any app not to upload my contact list?
- deleted 7y ago[deleted]
- minitech 7y agoThe SSLKEYLOGFILE approach is a good one; the warning being considered for Chrome just makes it clear when it’s in use. (Not that you could detect it by inspecting decrypted HTTPS if a closed-source app really wanted to secretly upload your contact list. In that sense, security best practice is minimal app permissions and reproducible builds.)
- xg15 7y agoIt's also formulated in a way that clearly implicates "this is bad, don't do that!". The warning makes sense if shown as part of a shortlived debug session to a developer. However, this is caused by a program that a non-technical user has installed permanently on the device. So I'm confused how legitimate TLS inspection is supposed to work for this user group.
- theamk 7y agoI think the Google's answer is, "it isn't supposed to work" They pretty clearly believe that they should be the only ones controlling the web experience.
- xg15 7y ago> Not that you could detect it by inspecting decrypted HTTPS if a closed-source app really wanted to secretly upload your contact list. In theory yes. If every app had their own hand-crafted binary format, scanners would be out of luck. However, in practice, developers value existing tooling and most of the actual data on the wire seems to be formatted in a manageable number of well-known formats (JSON, XML, url params, protocol buffers, etc). If nothing else, a scanner could at least find out with some reasonable certainty that an app is trying to obfuscate something. I think the amount of detection and analysis tools that exist give some hinds that even if you cannot analyze everything, there is a lot of things you can find out. > In that sense, security best practice is minimal app permissions and reproducible builds. Reproducible builds of what? We haven't even got this to work for most open-source software and with closed-source software, you per defintion doesn't even have anything to build in the first place.
- imvetri 7y agoAround two weeks back chrome hid its address bar. Could it be a coincidence or both are related?