5 ms·
> fallsback to http:// http:// only when necessary and only when the website was not MITM-ed How would you know when an HTTP site is being MITM'd? There are so
by rictic 6y ago
> fallsback to http:// http:// only when necessary and only when the website was not MITM-ed
How would you know when an HTTP site is being MITM'd? There are some easy cases, but for everything else, well, ensuring this is half the point and most of the operational complexity of HTTPS!
- cookiengineer 6y agohttps is used primarily. If there's only http available, trusted peers are asked for two things: their host caches for that domain and whether or not the data was transferred securely via https (port and protocol). If either of those isn't statistically confirmed, it is assumed that the targeted website is compromised. Currently I think this is an as good as possible approach, but otherwise I have no idea on how to verify that the website is legit without introducing too much traffic overhead for the network. Personally, I wouldn't trust any http or https with tls < 1.2 website anyways. But whether or not that assumption can be extrapolated...dunno. Do you have another way to verify its authenticity in mind?
- rictic 6y agoI don't. Authentication is a pain, and the later in the stack you try to solve it the harder and hackier it gets. We have the gross hack of certificate authorities because we failed to deliver authenticated information via the domain name system. > their host caches for that domain Hm, would this trip a MITM flag if someone switched hosting providers? Like, if example.com is http only and is moved to a new datacenter, is there a way to distinguish this from someone MITMing the traffic?
- cookiengineer 6y agoAs of now, a change of server ips would trigger an MITM warning if the new server is still served via http. If it's https and has identical hash content values, it is currently assumed to be the same server. I basically decided to do this equivalent of statistical certificate pinning because I have no better solution at hand. I mean, you could have a couple of servers hosted in different geolocations and assume that if they crawl it and it's identical, then it must be true...but usually state level actors block it in the originating country, so it's hard to trace without something like a censorship index by geolocation (which is my plan for now). But honestly, I have no way to know whether this will work out, because every piece of the internet's infrastructure can be potentially infiltrated. I mean, that is ethernet by design.
- Sephr 6y agoThe solution that you're looking for is SXG (Signed HTTP Exchanges)