5 ms·
Honest question, is it possible to have chrome disable the functionality to export the SSL private key? IE on that notification is there a button to deny the s
by Rudi9719 7y ago
Honest question, is it possible to have chrome disable the functionality to export the SSL private key?
IE on that notification is there a button to deny the stream?
- jackewiehose 7y agoWhy should they do that? This is a developer option that has to be explicitly turned on. If you don't want that, don't turn it on. I don't think normal software should need to take account of every way anti-viruses might abuse features.
- gempir 7y agoChrome isn't exporting the private key. It's importing the key you give it. Idk for what that is useful besides Virus Scanners, but personally I would like my browser to make its own key and never leak it or accept new ones.
- tialaramex 7y ago> Chrome isn't exporting the private key. It's importing the key you give it. No. It is _exporting_ the _secret_ key. It can't import the key, in many modern key agreement schemes neither client nor server gets to dictate the keys used, if you used a fixed or predictable value instead of a random one you just give up your security, you gain nothing. So the keys are (and should be) random for each session.
- tialaramex 7y agoWhat private key? Again, these are _secret_ keys. That's why the word SECRET n capital letters appears in that output at the end. Symmetric cryptography is used to actually transport data, and so it uses secret keys. These are agreed between client and server for each session and by getting a copy of them you can read (and in principle modify) the data as it passes between them. A private key would be a key that only one party knows. The notification is a reminder that this is an unsupported configuration of the browser software, useful for developers but not really intended for your garbage "Anti-virus" software to try to hook into. Just remove/ disable the AV?
- drewg123 7y agoThat's a good question. It seems like Chrome may be able to clear the environment variable so the TLS libraries don't see it.
- xg15 7y agoTo my understanding, this exports the session keys of an active TLC connection. Those are temporary keys that were created during the handshake of a particular TLS connection and are only valid for this particular connection. So, if this data is picked up immediately by a network sniffer, it can decrypt the currently active TLS connection. However, the keys will not allow anyone to decrypt any past or future connections.
- ldoughty 7y agoThis should be correct. This is super useful for developers and operations people to debug traffic ... Or for security/monitoring software (e.g. company or parents monitoring people). But limited use otherwise. Considering the hoops you go through to turn this in, this is usually okay, but it is not necessarily apparent to end users when it is on.
- topranks 7y agoIt may be but these keys are ultimately in RAM. If you are root on the local system (as all AV is,) then ultimately you can collect these keys, the only question is how much work you may have to do.