7 ms·
Hilarious. And they’re referencing specs so deep nobody understands what they’re talking about. Certificates are BS.
by sqldba 6y ago
Hilarious. And they’re referencing specs so deep nobody understands what they’re talking about. Certificates are BS.
- wrkronmiller 6y ago> I've flagged this as a SECURITY matter for CAs to carefully review, because in the cases where a third-party, other than the Issuing CA, operates such a certificate, the Issuing CA has delegated the ability to mint arbitrary OCSP responses to this third-party! > For example, consider this certificate https://crt.sh/?id=21606064 https://crt.sh/?id=21606064 . It was issued by DigiCert to Microsoft, granting Microsoft the ability to provide OCSP responses for any certificate issued by Digicert's Baltimore CyberTrust Root. We know from DigiCert's disclosures that this is independently operated by Microsoft.
- zeveb 6y ago> Certificates are BS. Pretty much. The whole business model never really made sense: the relying parties have no relationship with the certificate authorities, while the HTTPS servers are the customers of the CAs. I think it would make a lot more sense for certificates to be issued by domain owners, esp. since the original idea of tying sites to real-world businesses (e.g. with Dun & Bradstreet numbers) has been reduced to just verifying domain-name ownership. Edit: I think people misunderstand what I am saying here. What I mean is that I think that when one purchases a subdomain of domain, that domain should just issue a certificate — and that domain should only be allowed to issue certificates for its children. So e.g. if one purchases foo.com, then com issues a certificate for foo.com; if one purchases bar.net, then net issues a certificate for bar.net; if one purchases baz.ac.uk then ac.uk issued a certificate for baz.ac.uk. This is essentially what Let's Encrypt and ACME already do: com has the technical ability to reassign any of its subdomains at any time it wants to, and can get a certificate issued for any of them by reassigning & registering a certificate. And while we're at it, maybe we could kill ASN.1 with fire? Edit: if you downvoted for this, you have never tried to debug an ASN.1 BER file.
- microcolonel 6y agoThen there's the whole issue of putting domain names/common names inside the certificates, but relying on external verification; rather than just having the DNS NICs directly sign for domains they have obvious authority over.
- arp242 6y ago> I think it would make a lot more sense for certificates to be issued by domain owners, esp. since the original idea of tying sites to real-world businesses (e.g. with Dun & Bradstreet numbers) has been reduced to just verifying domain-name ownership. The problem with that approach is that anyone can create a certificate for any domain; so if I go to "example.com" then it's kinda hard for me to detect if my connection is being MITM'd, especially if this is the first time I'm visiting example.com. This is why ACME requires a verification that you actually control example.com (via http or dns). I don't think the CA model is perfect by any means, but I don't think it's completely without value either.
- ocdtrekkie 6y agoDNS providers should be your HTTPS providers though. Presumably the certs your browser would have to "just know" would be for the root TLDs, so you could verify with them what DNS provider a given domain was entrusted to, and then query that DNS provider whether or not your domain's certificate was legitimate. The idea that any CA can issue a valid cert for any domain is the heart of what's wrong with PKI.
- brohee 6y agoThe name constraint extension (https://tools.ietf.org/html/rfc5280#section-4.2.1.10 https://tools.ietf.org/html/rfc5280#section-4.2.1.10) can help a lot with that, we chose to trust CA for all names but we could have had CAs for a way more limited set of domains. Software support is far from universal sadly.
- ocdtrekkie 6y ago> original idea of tying sites to real-world businesses Ironically, the only system PKI had to attempt this, Extended Validation, is opposed by the loudest voices in PKI today. Despite arguably being the only real benefit PKI potentially offered: Notarizing that a domain really belonged to a given real-world entity. EV had flaws, but it should've been improved, not axed. Security detached from people-understandable real-world entities will never provide real security, because at the end of the day people still need to interact with the system.
- stefan_ 6y agoI thought the BS here was that this compromises OCSP which no one uses regardless due to its numerous design faults.
- user5994461 6y agoYep. Revocation was broken by design so hardly anything supported it, and now the implementation is broken so revocation is getting revoked. The whole thing is ridiculous.
- _wldu 6y agoComplexity kills.
- KevinIsMyName 6y agoIndeed.
- ocdtrekkie 6y agoIndeed. I am still in awe people supportive of PKI are referred to as "security experts". PKI is literally where we decided that a bunch of companies nobody's heard of should all be the Most Trusted for the entire Internet, and be able to tell us if everyone else is trustworthy. And then our web browsers, one of which is run by an adtech company, should decide whether or not to trust those entities, and whether or not to let the user override that decision about trustworthiness, to show us the website we wanted to get to.
- simias 6y agoIt was supposed to be a "proof of stake" originally I suppose, if a company was caught doing shady thing it would lose its CA status so they're incentivized not to do so. Sort of like internet notaries. That might have worked decently in the early internet but it does seem seriously flawed with the current stakes. That being said, what's the alternative? TOFU? Web of Trust? Those have massive security implications as well. They have the advantage of putting the user back in control but given that the vast majority of the people using the web today doesn't have a deep understanding of the underlying technology and security model I don't see how this wouldn't end up in a massive catastrophe. It's a tough problem to solve.
- ocdtrekkie 6y agoThe problem is a lot of companies have done shady things and they are still participating in PKI. And a huge issue is that I can't pick my trustworthy parties: For instance, I do not trust Google. But a huge portion of the web won't work unless my browser assumes Google can issue certs for any domain in the world. I also don't trust a half a dozen CAs in countries I don't deal with and would rather prefer not have access to at all. When a Chinese PKI provider fails, I first wonder why I'm even trusting these CAs to begin with. I'd prefer a system backed by DNS, and based on verifying the ownership of domains and the authorized DNS provider for that domain. Presumably, in my example, the only domains Google would be authorized to secure would be domains provided via Google's DNS and domain products.
- 6y ago
- tptacek 6y agoIf certificates are BS, give me hosts.txt entry I can point INSTAGRAM.COM that my browser will actually honor. It should be easy. Certificates are problematic. But that's because the world is problematic. They were much more problematic 10-15 years ago. Google and Mozilla drastically mitigated their problems. They're still imperfect, but anything that expresses web trust across the entire world is always goign to be imperfect, and the webPKI at least has some stakeholders that are both empowered and deeply give a shit about security.