3 ms·
No, you can do something like CloudFlare does for TLS for their enterprise customers, where the TLS session is signed by a key held by Netgear. https://www.clo
by CiPHPerCoder 7y ago
No, you can do something like CloudFlare does for TLS for their enterprise customers, where the TLS session is signed by a key held by Netgear.
https://www.cloudflare.com/ssl/keyless-ssl https://www.cloudflare.com/ssl/keyless-ssl
The fallback would have to be self-signed TLS with random keys for initial local router configuration, which is hopefully done over an Ethernet connection rather than WiFi.
You don't need a secure enclave or HSM to solve this problem. It just requires caring about security and provisioning enough time to engineer and test the obvious solution. From what I can tell, that doesn't line up with Netgear's MO.
- lima 7y agoThat would be a central point of failure and a ton of extra complexity without providing any kind of meaningful security benefit.
- CiPHPerCoder 7y agoWhat do you mean "without providing any kind of meaningful security benefit"? It prevents a bored kid who dumps the private key from one router from being able to reliably impersonate thousands of consumers' routers, the world over. That's a meaningful security benefit.
- lima 7y agoThe attacker would just dump the individual router's key instead and use the remote signer as a signing oracle to impersonate devices.
- CiPHPerCoder 7y agoThe owner/operator of the router could do that to their own device, yes. The idea is that each router would get a certificate signed with a distinct subdomain unique to that router. So you still can't impersonate other devices. It wouldn't be a generic domain or wildcard certificate. The remote signer would furthermore suspend suspicious connections (i.e. from multiple public IP addresses).
- gsich 7y agoYou need a working internet connection. In most cases you go to the webinterface because you are either setting it up, or something (most likely connection) doesn't work.