5 ms·
> SSL certificates handled in a SSH-like manner > CAs are ignored, the only thing that matters is that the cert does not change. With today's rogue CAs and gov
by CyberShadow 5y ago
> SSL certificates handled in a SSH-like manner
> CAs are ignored, the only thing that matters is that the cert does not change. With today's rogue CAs and governments, this policy is better suited for detecting man-in-the-middle attacks than a browser blindly trusting a CA.
I'm not sure this is a good idea. SSH best practice is that you acquire the server's key fingerprints via a previous secure channel. E.g., Hetzner will email them to you when they set up your server.
- chasil 5y agoIt would be nice to merge the two approaches. -Attest a CA for initial connection -Alert on change, include CA details, with option to (not) override cache Will this browser make it into EPEL?
- j16sdiz 5y agoIMO, HSTS handle it better
- jcranmer 5y agoDon't worry. If I'm following the code correctly, then the definition of "the certificate changed" is "either the issuer name, notBefore, or notAfter fields change." Unless you are Google, Cloudfare [1], or the issuer is Let's Encrypt, in which case that check isn't bothered with as those sites update too frequently. No need to worry about, let's say, the public key possibly different. I'm not sure how much of the rest of the certificate process is being done (e.g., making sure that the cryptographic signature is valid), since I'm not savvy on OpenSSL's APIs to know what you do yourself and what OpenSSL does for you. Even for a TOFU implementation of SSL, this repository is amazingly bad. [1] Yes, those site names are hardcoded. By server name. So anyone could MITM google here. Or cdnjs.cloudfare.com.
- hulitu 5y ago> I'm not sure this is a good idea. SSH best practice is that you acquire the server's key fingerprints via a previous secure channel. E.g., Hetzner will email them to you when they set up your server. email != secure channel
- CyberShadow 5y agoDKIM provides integrity, which is what is important here.