4 ms·
Many enterprises use a FIPS SSL proxy for all employees web traffic, so all websites with these lets encrypt will effectively be invalidated if the proxies are
by aisio 5y ago
Many enterprises use a FIPS SSL proxy for all employees web traffic, so all websites with these lets encrypt will effectively be invalidated if the proxies are using openssl FIPs modules, same for FIPS client side applications
- tyingq 5y agoI don't have a lot of sympathy for the companies in this situation. If you want to MITM all your employee's traffic, then you accept the burden of dealing with stuff like this periodically.
- jeroenhd 5y agoIt seems quite silly to me to enforce a massive MitM attack while at the same time sticking to the FIPS standards. Then again, a lot of governmental and financial security requirements are nonsensical to me, like mandatory password changes. When I, as a website host, need to choose between accepting millions of Android devices or a few organizations with an esoteric security configuration, I'll go for the Android devices. AFAIK Windows FIPS mode is unaffected by the OpenSSL bug, so not all FIPS modules will have trouble with the Let's Encrypt certificate. A Windows-based MitM-attack won't have this problem. The best solution here would be for OpenSSL to have a FIPS release ready before September, or to release a patched version of 1.0.X, but that still won't help companies that cannot or will not update their software.
- 0xbadcafebee 5y ago> It seems quite silly to me to enforce a massive MitM attack while at the same time sticking to the FIPS standards. Well they're two different things. One is an often government-mandated security standard. The other is a business requirement to be able to audit network traffic, which is also often a government-mandated requirement (due to regulations, due diligence, contractual requirements, etc). People making tech stuff very often forget that the entire world does not work based on "technical best practices", it works on laws and contracts and customer/business requirements. In the real world there is often no perfect way to satisfy all requirements.
- jeroenhd 5y agoThe reason the government wants FIPS is that it's been verified to be secure according to the national agencies. Enforcing that that security and then putting all if your sensitive traffic in the hands of one key on one box directly contradicts the security requirements FIPS is intended to ensure. I don't expect the government to have different departments work together around this stuff, but knowing the technical details, the end result is still impractical and stupid. The end result of stupid rules and requirements is that the real world application of technology is stupid, as we have probably all experienced one way or another during our lives. Just because there's a real business need for something, doesn't stop that from being silly. Correcting the silliness is clearly not a technological challenge, we'll have to wait for politicians and managers to do that, but the end result is still a confusing and contradictory mess.
- alias_neo 5y agoSome of it is misguided, some of it is legacy, other parts _do_ make sense to the people involved. Mandatory password changes for example have not been recommended[0] by NCSC in the UK since ~2018. Continuing to do so is either legacy or misguided. As for "MitM" it's usually due to regulatory requirements to protect and inspect at boundaries to and from an organisations network. FIPS and OpenSSL is an interesting subject. Many organisations rely on it, yet relatively few contribute financially. When 1.1.X and subsequent versions came along and had no FIPS 140-2, orgs were forced to wait it out until someone else pays to get it accredited or pony up and help the process along. I haven't looked lately at how much has been contributed to the effort but I suspect it's still pretty low considering how much of the world relies on OpenSSL. [0]https://www.ncsc.gov.uk/collection/passwords/updating-your-approach https://www.ncsc.gov.uk/collection/passwords/updating-your-a...
- slownews45 5y agoMandatory 90 day password changes are still required by the IRS in the US at least. High complexity / weird rules too - and not one password across systems as they have endless DIFERRENT login systems. So your tax software itself will require 90 day resets for all staff using that, every interface to IRS requiring it (which means every login for little used systems). It's bonkers. My worry - how do they even correlate / track login risk given all these different systems. Google (which has never required a password rotation) seems to be able to really figure out when risk is higher (new device from a new location) and lower (same device from 5 minutes ago). That makes turning on 2 factor with a hardware device MUCH easier - because it doesn't annoy you unnecessarily.
- alias_neo 5y agoOuch that sounds painful. If I'm not mistaken, all/most Americans have to interact with the IRS regularly? So this is an issue for many of you? By that I mean as a Brit who is salaried (PAYE) and doesn't own a business I have never had to interact directly with HMRC so even if it was as bad (it's not) it would be an infrequent experience.
- 5y ago
- hannob 5y agoI guess that will give them an incentive to fix those devices quickly.
- josephcsible 5y agoHa, good one. For the average company that breaks SSL, I expect something like this instead: "new corporate policy update: for security reasons, you're no longer allowed to visit HTTPS Web sites that use Let's Encrypt. If the Web site you want to visit still allows HTTP, that continues to be acceptable."
- hannob 5y agoAin't gonna happen. Let's Encrypt is too big to be ignored. You can't practically use the web like that.
- josephcsible 5y agoWe know this, but I don't think everyone does. I'm sure that at least some places will learn this the hard way.
- 0xbadcafebee 5y agoThey will just add an additional TLS proxy with a self-signed cert that ignores all validation. Security will be broken but users will be able to continue to do their work.
- hannob 5y agoMaybe we just had a misunderstanding. What I was trying to say: Once this happens and everything breaks they will have an incentive to fix things quickly. By no means do I expect vendors of "SSL inspection" devices to act any sooner than that.
- ethbr0 5y ago> You can't practically use the web like that. is looking at a corporate firewall blocking Stack Overflow right now ... "practical" is setting your expectations a bit high.