3 ms·
Yes, if you have access to a root CA you can generally speaking man-in-the-middle HTTPS traffic. One defense is HPKP [1], where a certificate or root of trust i
by y7 5y ago
Yes, if you have access to a root CA you can generally speaking man-in-the-middle HTTPS traffic. One defense is HPKP [1], where a certificate or root of trust is pinned so it cannot be substituted. But it's a bit tricky to implement, because if you make a mistake you can lock yourself out as server administrator. I think some browsers also hard-pin some certificates, like Chrome does for Google domains.
There's also Certificate Transparency [2] which maintains append-only logs of all issued certificates. I'm not really sure how widely it's implemented in browsers, or whether it can be bypassed somehow.
1. https://en.wikipedia.org/wiki/HTTP_Public_Key_Pinning https://en.wikipedia.org/wiki/HTTP_Public_Key_Pinning
2. https://en.wikipedia.org/wiki/Certificate_Transparency https://en.wikipedia.org/wiki/Certificate_Transparency
- mgdm 5y agoI don’t believe any modern browser supports HPKP any more, due to how hard it was to set up and operate.
- LinuxBender 5y agoThey still honor it. I have to tell squid which domains to not MITM because some of Google's sub-domains, paypal, the EFF and a few others still use it.
- toast0 5y agoI suspect all of those pins are from preloading (arranged by request with Chrome maintainers) and not HPKP. HPKP was supposed to allow for similar security after first use, without needing to interact with maintainers and wait for a browser release, but because of the probability of shooting your own foot, usage was extremely low and it was on the path to removal, last I checked.
- fulafel 5y agoNote that most browsers allow MITM in presence of HPKP in certain circumstances to facilitate interception by schools and corporate IT. (Mentioned also in your linked WP article - "Most browsers disable pinning for certificate chains with private root certificates to enable various corporate content inspection scanners")