3 ms·
In the spirit of asking silly questions (as encouraged in some comments here), here's mine: My small SaaS company's PostgreSQL RDS instance and app servers are
by dperfect 7y ago
In the spirit of asking silly questions (as encouraged in some comments here), here's mine:
My small SaaS company's PostgreSQL RDS instance and app servers are in a VPC with security groups configured to only allow connections from the app servers to the DB (no public access to the RDS instance). My client (ruby-pg) on the app servers is connecting via SSL, but not currently with certificate validation (though I believe the cert date still needs to be valid [?], hence the need to rotate the PostgreSQL server's certificate).
In this scenario, how important is certificate validation? I understand the theoretical risk of clients not being able to fully trust that they're connected to the database I intend, but from a practical standpoint, it seems that if an attacker is able to poison the VPC's DNS and trick the app servers into connecting to something else, I'm already hosed and cert validation wouldn't do much to help me. Am I missing something obvious and very dangerous?
- luhn 7y agoAWS claims that VPC traffic is immune from MiTM attacks. [0] (Although they strangely don't talk about this much, and I can't even find official documentation of it.) So within a VPC, you can forgo certificate validation. However, in general certificate validation would protect you. The attacker wouldn't have a valid certificate, so your application would refuse to connect to the malicious endpoint. [0] https://kevin.burke.dev/kevin/aws-alb-validation-tls-reply/ https://kevin.burke.dev/kevin/aws-alb-validation-tls-reply/
- arkadiyt 7y agoThey do talk about it in their Advanced Networking Study Guide: https://twitter.com/0xdabbad00/status/995833462660612096 https://twitter.com/0xdabbad00/status/995833462660612096
- stingraycharles 7y agoSo basically they intercept all ARP communication and add VPC header information to all Ethernet packets, which should rule out any MITM scenario. Of course the keyword here is “should”, and depending on your threat mode you may or may not want to have an additional defense layer of SSL certificate validation.