3 ms·
Web PKI (or really, the web) is reasonably OK for peactime but is not going to survive very well at a "wartime footing". There are some attempts with Certifica
by outsomnia 5y ago
Web PKI (or really, the web) is reasonably OK for peactime but is not going to survive very well at a "wartime footing". There are some attempts with Certificate Transparency
https://en.wikipedia.org/wiki/Certificate_Transparency https://en.wikipedia.org/wiki/Certificate_Transparency
to make it more visible if unreasonable but valid and trusted certificates (eg, a trusted Russian CA signed cert for google.com) are seen.
Sites can tell browsers what CA they should expect from that site
https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Expect-CT https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Ex...
if something else is seen, it tells the browser where to report it. This helps but if the attacker controls the victim routing it can suppress the reports.
Browsers ship trusting pretty much every country's CAs at the moment, which is convenient. If CAs are found to be mis-issuing certs, they will get distrusted from the browsers, which has happened several times already. But in wartime, they are not going to care about that if they can inflict massive damage first.
- wg0 5y agoThat's interesting. But let's say I am a nation state hell bent on intercepting everything or even a major ISP in the region, can't I remove Except-CT header from all outgoing HTTPS responses?
- rand846633 5y agoThe requests containing Expect-CT headers are already encrypted, so how can you remove them?