3 ms·
They should be downloading a bloom filter of revoked certificates, instead of checking with a server every time. This is known as CRLite, and Firefox is implem
by tbodt 6y ago
They should be downloading a bloom filter of revoked certificates, instead of checking with a server every time.
This is known as CRLite, and Firefox is implementing it for HTTPS certificates. https://blog.mozilla.org/security/2020/01/09/crlite-part-1-all-web-pki-revocations-compressed/ https://blog.mozilla.org/security/2020/01/09/crlite-part-1-a...
- chrisshroba 6y agoSince Bloom filters allow for false positives, wouldn’t that make them inappropriate here? You wouldn’t want a valid certificate to be perceived as revoked. (I recognize that I’m probably wrong, given that Mozilla is doing this - where is my mistake in logic?)
- saagarjha 6y agoThat would be better than what we have here, though, where every application launch gets checked. The fallback with a Bloom filter is that you check a few apps, not all of them.
- chrisshroba 6y agoIt’s better with a trade off. It removes the call-home to Apple, but adds the possibility of false positives for certificate revocation. Is this in fact the trade-off we’re considering, or am I misunderstanding?
- sirsar 6y agoYou are misunderstanding. The bloom filter is only a preliminary check; if it indicates a revoked certificate, you then verify that it's a true positive the traditional way.
- chrisshroba 6y agoOh of course. Thank you for clearing that up for me.
- adinisom 6y agoI think the idea is that false positives (cert revoked) result in a call home to Apple for an actual check. The other idea is that because Apple knows all existing certificates, they could conceivably construct filters that have no false positives for those existing certificates... sort of like construction of a perfect hash.
- tbodt 6y agoMozilla's solution to this is to run every single certificate in the CT log through the filter, and remedy any false positives with an extra layer. The filter also has a date attached, so potential false positives that are newer than the filter can be checked with OCSP. https://blog.mozilla.org/security/2020/01/09/crlite-part-2-end-to-end-design/ https://blog.mozilla.org/security/2020/01/09/crlite-part-2-e...
- sneak 6y agoIt’s just a precheck filter, where the bloom filter negative is the majority path, cutting out (the vast majority of) the leak. The bloom filter positives still get normal checks.
- LeCow 6y agoTechnically that's also possible with cryptographic hashing functions, but we still use them.
- est31 6y agoI really like this because of the increased privacy (apple doesn't know which apps you run) as well as the better error mode. If their servers go down, the worst that can happen is that an update of the revocation list fails, which means they can't get new revocations out to people. But it's not that apps won't start any more.