2 ms·
WebPKI doesn't really solve these problems. CA Audits are mostly about ensuring they're following the rules. However, the rules cannot stop an ISP or hosting p
by native_samples 5y ago
WebPKI doesn't really solve these problems.
CA Audits are mostly about ensuring they're following the rules. However, the rules cannot stop an ISP or hosting provider just issuing themselves a cert and a fully audit compliant CA is not expected to stop this.
Cert transparency is mostly unused. For it to work people have to proactively search the logs to find certs they didn't issue, but in reality nobody does this outside of maybe big tech firms. Moreover, in the ISP/colo interception case, the CA wouldn't be revoked because they wouldn't have done anything wrong.
Re: pinning. You can't pin if your IP isn't stable. However you can if you're a server. Then you don't need the fragile link of DNS in the loop at all. For instance, mobile apps can just have a cached public key (of course you can do that today, but we're talking about a system that is more deeply integrated with the internet).
"there is no single attacker who is on path for all of lets encrypt's vantage points"
No? AWS isn't on path for all the websites they host?
Even in the case where the hardware isn't owned, any site that has one internet uplink (i.e. most of them) can be targeted in this way.
- bawolff 5y agoHmm. You make some good points.