4 ms·
Multiple reasons: 1. Firefox remains the only mainstream browser to support OCSP Must Staple. 2. OCSP Must Staple does not cover all threat models: if an atta
by pfg 7y ago
Multiple reasons:
1. Firefox remains the only mainstream browser to support OCSP Must Staple.
2. OCSP Must Staple does not cover all threat models: if an attacker gains the ability to temporarily issue certificates for the victim's domain (rather than obtaining the private key of an existing certificate), they can request a certificate without the OCSP Must Staple extension. A more effective method would be something like the Expect-Staple header[1] (in enforce mode).
3. It allows the ecosystem to move significantly faster. In a world where all certificates expire after 3 months, phasing out insecure hash algorithms (in certificates) would no longer take many years.
4. It encourages regular key rotation (even if it's not enforced)
[1]: https://scotthelme.co.uk/designing-a-new-security-header-expect-staple/ https://scotthelme.co.uk/designing-a-new-security-header-exp...
- wbond 7y agoItems 3 and 4 seem like weak arguments. We are still dealing with operating systems from 3+ years ago, so moving below a 1 year certificate length wouldn't buy much agility in terms of new algorithms.
- pfg 7y agoHash algorithms may not have been the best examples as they require client support. A better example would be something like Certificate Transparency. Currently, browsers may require Certificate Transparency for certificates issued after a certain date. A malicious or compromised CA may work around this by backdating certificates. This would be less of an issue with shorter certificate lifetimes.