3 ms·
OP is talking about system 1 getting a response generated by system 3 VIA system 2 (potentially trusted man in the middle). And they are already assuming that
by codegladiator 7y ago
OP is talking about system 1 getting a response generated by system 3 VIA system 2 (potentially trusted man in the middle).
And they are already assuming that system 1 and 2 talk using https and system 2 and 3 talk using https.
- speedplane 7y ago> OP is talking about system 1 getting a response generated by system 3 VIA system 2 (potentially trusted man in the middle). So they are effectively saying that they do not trust system 2. If that's the case, a signature from system 2 would not help because the signature itself could not be trusted. They would need the signature from the original source, system 3.
- codegladiator 7y ago> a signature from system 2 That's why they are talking about signature from system 3 along with the payload. So even if they trust system 2, they can be sure system 2 has not tampered with the message generated by system 3.
- speedplane 7y ago> That's why they are talking about signature from system 3 along with the payload. So even if they trust system 2, they can be sure system 2 has not tampered with the message generated by system 3. No that wouldn't work by itself. System 2 could tamper the data, create their own signature, and send it to system 1. The only way it could work is if System 1 got the signature directly from System 3, or at least got System 3's public signing certificate. Either way, System 1 needs to communicate directly with System 3 to ensure the data it's getting from System 2 is authentic.
- codegladiator 7y agoI think you are right. At some point system 1 will need to talk to system 3 to validate the message (unless system 1 and 3 have an already shared secret or public key)
- speedplane 7y ago> I think you are right. ... At some point system 1 will need to talk to system 3 to validate the message Yes, this is why any post claiming to "roll their own security" is a farce. The current way security works (using HTTPS) is to pre-install trusted certificates on the machine at the hardware manufacturer or OS installation level. The keys that are pre-installed are this initial high level (usually root certificates), can then secure lower level machines, which can further secure even lower level machines. This only works because we trust our hardware manufacturers (e.g., Dell, HP, etc.) to install the correct certificates. These manufacturers are analogous to "System 3" in the example above.