5 ms·
Very probably I'm missing something, and I love Let's Encrypt and the service that they provide, but... the point of Let's Encrypt is to bring SSL/TLS to more w
by zanecodes 6y ago
Very probably I'm missing something, and I love Let's Encrypt and the service that they provide, but... the point of Let's Encrypt is to bring SSL/TLS to more websites, right (and not necessarily to provide identity verification, since the automated renewal process doesn't really require any proof of identity for the entity requesting the certificate)? Why couldn't that have been accomplished using self-signed certificates, and having browser vendors remove their big scary warning pages for sites using self-signed certificates for SSL/TLS?
Do certificates from Let's Encrypt provide any security benefits over a self-signed certificate?
- gsich 6y ago>Do certificates from Let's Encrypt provide any security benefits over a self-signed certificate? Depends. The encryption is the same and only dependent on your client/server. Could have been solved by DNS ... maybe. Self signed certs don't validate that you at least own the domain.
- zanecodes 6y agoAh yes, that makes sense. Let's Encrypt requires proof of domain ownership, which at least ensures that the entity you're connecting to is the entity that owns the domain. Encryption without authentication wouldn't be very helpful, since a man-in-the-middle could just present their own self-signed certificate during the handshake...
- tialaramex 6y agoYou'd be protected from a passive attack and thus you could always (with enough effort) detect an attack. Someone who is snooping (e.g. fibre taps) is potentially undetectable (yes in theory there are quantum physics tricks you could do to detect this, but nobody much is really doing that) whereas an active attack is always potentially detectable. So it's not nothing, but it isn't very much without the Certificate Authority role.
- VoidWhisperer 6y agoThe issue with browsers just allowing self-signed certs is that you cant verify their authenticity - ie were they correctly issued for the domain, or is it someone acting as the website using an invalidly issued cert. Having certs come from a recognized certificate authority helps with this because it provides a point for the certificate to be verified for authenticity
- zanecodes 6y agoThis makes me wonder about the feasibility of performing an attack by * man-in-the-middling Let's Encrypt and a particular domain (or DNS, depending on the domain validation challenge) * requesting a new certificate for that domain * spoofing the HTTP resource response (or DNS response, if applicable) I suppose this is mitigated by the way Let's Encrypt validates the agent software's public key on first use though, at least for websites that are currently using Let's Encrypt.
- level3 6y agoLet's Encrypt also mitigates this by validating from multiple vantage points, so a single man-in-the-middle is insufficient.
- Denvercoder9 6y ago> man-in-the-middling Let's Encrypt and a particular domain (or DNS, depending on the domain validation challenge) Let's Encrypt issues multiple verification requests from multiple servers in different locations, both physically and in the network topology. If you can MITM that, you've pretty much taken over the domain and the ability to get a certificate isn't the worst of the operators problems.
- marcosdumay 6y ago> and the ability to get a certificate isn't the worst of the operators problems That assumes a lot about the operators goals and values. It may very well be their worst problem. Eg. a journalist in a dictatorial area will very likely prefer not to have a cloud service than to upload his data into some compromised service. It's just that, if it is their worst problem, TLS is patently insufficient, so they must think about it when setting the system up.
- jaywalk 6y agoThey verify domain ownership. If browsers accepted self-signed certificates, then as long as I could intercept your DNS requests (running a public Wi-Fi network next to a Starbucks, for example) then I could bring you to my malicious google.com without you knowing. That's no good.
- M2Ys4U 6y ago>They verify domain ownership. They verify domain control, not ownership. Verifying ownership is a much harder problem, and one I doubt could be done in an automated fashion.
- acct776 6y agoHighly recommend reading someone's applied essentials guide on certs, and the various methods of accomplishing SSL for self-hosted stuff. This stuff is much more complicated in isolation from the rest - full picture easiest.
- zanecodes 6y agoI'm somewhat familiar with certificate handling in general, I had just forgotten how Let's Encrypt performs domain validation; it's been a few years since I used it and it's worked so well that I haven't had to think about it since, which is probably a testament to its stability! To be sure, PKI and certificates in particular have a lot of room for improvement in the UX department. Especially on Windows, where one frequently has to deal with not just .pem files but .cer, .pfx (with or without private keys), and more.
- Jonnax 6y agoThose scary warning pages are an indication that someone is intercepting your traffic. What do you think about connecting to a network, and your phone sends a user/password to a server but instead it's being intercepted? And the user has no idea.