5 ms·
Correct me if I am wrong, but it seems like firefox (and maybe chrome) would never have this vulnerability as they use their own cryptography libraries for ever
by SolarNet 7y ago
Correct me if I am wrong, but it seems like firefox (and maybe chrome) would never have this vulnerability as they use their own cryptography libraries for everything.
- munchbunny 7y agoMaybe. The question isn't "are you using your own cryptography libraries for cryptographic operations." The question is "are you using Windows's native certificate chain validation API, or did you write your own?" Even if Firefox/Chrome use their own implementations of cryptographic algorithms, there's a decent chance that they are still using Windows's native API for certificate chain validation in order to plug into the enterprise certificate management features that come baked into Windows, which IT teams sometimes use to distribute internal PKI's. Without having seen how Firefox and Chrome deal with their chain building, I can't say "yes" or "no" definitively.
- SolarNet 7y agoLooking at it they don't even load crypt32.dll so unless one has a modified version of firefox, or an external plugin, it seems unlikely they have the vulnerability.
- munchbunny 7y agoIt looks like Chrome does: https://github.com/chromium/chromium/blob/ccd149af47315e4c6f2fc45d55be1b271f39062c/net/cert/cert_verify_proc_win.cc https://github.com/chromium/chromium/blob/ccd149af47315e4c6f... Credit to this person's comment in the Reddit discussion: https://www.reddit.com/r/netsec/comments/eooyil/cve20200601/feexbtt/ https://www.reddit.com/r/netsec/comments/eooyil/cve20200601/...
- tialaramex 7y agoFirefox uses only its own code, NSS, which is a Free Software crypto stack. This achieves consistency across OS platforms for Firefox. If Mozilla distrusts a sketchy CA then Firefox users are protected on a Mac just the same as in Linux, and in Windows. Firefox also uses NSS to do certificate validation. In newer releases a config pref lets you ask Firefox to use Windows' local trust store to find any CA roots that are being additionally trusted on your PC, e.g. "enterprise" certificates or even a local cert on somebody's local web development setup. But the validation for those certificates is still NSS. If your corporation has (as one of my ex-employers did) really half-arsed certificates they'll be rejected by NSS even though Windows is happy with them and Firefox has fetched them from the Windows trust store. This is potentially annoying but probably also means security at your place of work is shot to hell. Chrome on the other hand hands all normal certificate validation to Windows so as to deliver the same experience as other Windows products. This makes it a better drop-in replacement, but out-sources trust decisions (on Windows) to Microsoft. In this case that's bad news. For some certs Chrome will reject them because they either claim to be logged in Certificate Transparency (and the proofs won't match for a bogus cert) or they don't claim to be logged but they claim to have been created after that was mandatory. But bad guys could work around this (for the next year or so) by picking date ranges for which CT logging wasn't yet mandatory and yet a compliant certificate isn't yet expired. A proof-of-concept of this has been done for Chrome on unpatched Windows. Patching either Chrome or Windows to current fixes the problem for Chrome, but obviously patching Chrome doesn't fix other Windows software.
- reaperhulk 7y agoFirefox is not vulnerable, but (non-updated) Chrome actually is (until they replace the platform TLS verifier, which is happening soon).
- CiPHPerCoder 7y agoChrome already added countermeasures, if it was updated: https://chromium-review.googlesource.com/c/chromium/src/+/1998970/3/net/cert/cert_verify_proc_win.cc https://chromium-review.googlesource.com/c/chromium/src/+/19...
- technion 7y agoDoes anyone have a clear answer on exactly what version I need to look for/wait for to know this countermeasure is rolled out? Edit: Found it: https://chromereleases.googleblog.com/2020/01/stable-channel-update-for-desktop_16.html https://chromereleases.googleblog.com/2020/01/stable-channel... Version 79.0.3945.130.
- Fnoord 7y agoI suppose a home user desktop machine still uses Windows Update, and therefore downloads updates with an embedded Edge.
- deskamess 7y agoSo servers are not affected?