35 ms·
Everything we're told about website identity assurance is wrong
- xg15 5y agoGenuine question: suppose you get a link from a known, nontechnical friend for some interesting product on Amazon. The link goes to: https://amazon.shopping/ https://amazon.shopping/... How do you determine whether this is actually Amazon or a scammer?
- coldcode 5y agoSnake Oil is a long standing business practice.
- nailer 5y ago> Remember, EV only works if people change their behavior in its absence and clearly, that just doesn't happen. Web browsers told me they'd try better verification markers for years. They never did. So we don't know, except to say: a. the 'green bar' verification marker isn't very effective. b. the 'blue tick' logo as used for UIs like https://twitter.com/troyhunt https://twitter.com/troyhunt hasn't been tried so browser makers have no data here. It's a moot point: the realpolitik is browsers don't care about identity as it's not in their financial interest to do so. Disclaimer: I spent 5 years of my life trying to verify the web.
- nopenopenopeno 5y ago> “realpolitik browsers” So much truth expressed in this phrase. More than most of us would like to believe. This is why I can’t avoid reading HN.
- nailer 5y agoIf I had my time again I would have sold part of CertSimple to Google with the aim of integrating with Google My Business so Google would make money from verification. I feel this would prompt browsers to care about robust identity - both in terms of better verification and better display.
- bombcar 5y agoThe only real validation that actually works is certificate pinning built into the browser itself - and even that only guarantees that Google.com is signed by Google - not that goooooooogle.orgbiz.com.au is properly marked as a scam.
- nailer 5y agoThe term validation is overloaded so I’m avoiding it. EV is/was proof of identity. And proof of identity needs a scalable solution for the web. Certificate pinning won’t scale unless the browser knows all possible certificates in advance. Knowing whether something is a scam is a separate topic from verification. Think of other verification systems - people may be known, but bad. Admittedly twitter muddied the water here terribly by removing verification badges from people that twitter considers to have broken their terms of service.
- bombcar 5y agoThe problem is that proof of identity doesn't really give you much when you dig into it - either it's after the fact (which is what happens with EV, even if someone DID scam using one, AND it was traced back to what was likely a shell company). It's literally why banks were massive stone buildings - proving that they had the resources to build a solid thing that wasn't going to move or change was a part of establishing their identity as a something that can be trusted. So the equivalent for EV would have been to make them cost ... say ... $185,000 to register and $25k a year - wait, that's a TLD and would be a much more powerful form of identity and ... it's not used at all. https://google.google https://google.google redirects to ... google.com
- zaphar 5y agoI fundamentally think this is not a solvable problem using certs. Short of calling up the company directly and asking no amount of signaling in the browser will help. Also why do I care about an EV cert as a user? does it tell me anything actually useful? Things I do care about as a user: * Is my connection encrypted? (Browsers tell me this just fine) * Is the site known to be malicious? (Browsers tell me this just fine) * Have I been MiTM'd (Browsers protect against this just fine) Things I don't care about as a user: * Is this site actually owned by a specific Corporation? Literally have never cared. Not once. Knowing this has never made me more secure or given me more confidence because fundamentally knowing who someone on the internet is does not tell me how trustworthy they are without way more context.
- snowwrestler 5y agoYou don’t care if the banking website you’re using is actually owned by your bank?
- Karunamon 5y agoThe EV UI was sunset in all browsers because as it turns out, ensuring that your address bar says 'wellsfargo.com' and that you didn't get MITM'd is plenty good enough due to the other protections.
- deleted 5y ago[deleted]
- ROARosen 5y agoFor physical banks, every piece of stationary from my bank states their domain name so once I have a DV verified showing I'm actually connected to that domain I can trust it. For online banks, I only got to them online by which automatically means I have their correct domain name. The question of how I get the online bank's domain name to begin with does not really come in to this conversation, can be an ad, a friend etc.
- 5y ago
- newaccount74 5y agoI am soooo grateful for LetsEncrypt -- before them, getting certificates was such a hassle. Even if you didn't fall for the EV or OV or whatever certs, just getting a DV cert was annoying. Every vendor had a slightly different web interface that was really annoying to use, and to get the cheapest price you usually had to go through a reseller, and they had even worse web forms. LetsEncrypt is such a breath of fresh air. And the short 90 day validity period more or less forces you to set up an auto-renew script, so you can typically set it and forget it. And if you mess something up, they even email you to warn that your cert is about to expire!
- snowwrestler 5y agoLet’s Encrypt does a great job of enabling encrypted connections. But encryption alone is insufficient for security in financial transactions. You also need to verify that the entity you’re exchanging encrypted traffic with is the one you intended to do business with. How do you do that part today? Not via Let’s Encrypt.
- XorNot 5y agoSure but this is a problem the concept of web of trust should have solved for us if we had focused on government and enterprise buy in. For finance transactions there's basically a number of well known entities who should be vouching for the data I'm sending, who have large out of band systems for identity verification. Sadly none of that has happened.
- jacobwg 5y agoIs the domain insufficient? As an end user, that's the only signal I get, browsers are no longer showing me an EV certificate any differently than a DV certificate. If I'm communicating with mybank.com and I receive a valid DV certificate that was maliciously acquired, I have bigger problems than could be solved by EV certificates. I suppose Certificate Transparency is the tech working behind the scenes to flag mistaken or malicious certificates should they be issued.
- 5y ago
- bombcar 5y agoHa the example site at the end has already been taken down.
- chias 5y agoThe link and the url are not the same.
- snowwrestler 5y agoTroy and others have made great hay out of explaining how badly browsers work with EV certs. They spend considerably less time talking about why browsers do such a terrible job of surfacing cert information for website visitors. Yes, cert UI sucks; not sure we needed an enormous article to belabor that. The real question is, why does cert UI suck so bad? (UI design is a choice.) The answer is that everyone who runs a major browser has a vested interest in making sure decentralized site verification sucks. Because they are supported by highly centralized private site verification schemes. Decentralized verification is the norm offline. Do you carefully Google and research every store you walk into? No, because to open a store, the store owner has to establish a paper trail. And if you have a problem at that store, your advocate (a credit card company, insurance company, lawyer, law enforcement, etc) can follow that paper trail to find a party they can negotiate with, or investigate. Over time, the effectiveness of this system—in which all parties have invested—creates a barrier to in-person scams. The result is a society where you can walk into a new store, a restaurant, a bar, etc. with confidence. And note that name collisions don’t matter in this system. There are tons of restaurants called “McDonalds,” all owned by different people. But each one has an address and a unique paper trail that leads to a specific person or business. If you can remember which one you visited, your advocate can follow the paper trail for that one in particular. The idea of EV and OV certs was to use the power of encryption to hook your browser to this same set of offline paper trails. You wouldn’t even need to remember anything; the browser would maintain a log of the sites you visited for you. If you got scammed, you just look back in your history and forward the business info to your advocate or law enforcement. The decentralized nature was a feature; businesses had the choice of which cert to get, who to buy it from, and users had the choice of browser. Competition and mutual distrust would create incentives for parties to hold each other honest. To be clear, an EV or OV cert would not magically prevent scams. But they would provide cryptographic guarantees that an advocate or law enforcement could trace back to an entity, to prosecute or make you whole. Just like in a real life store. Instead, browsers became dominated by companies who run for-profit search engines, app stores, and identity platforms. So today what is the advice for verifying a website’s legitimacy? Google it. Or get their app from the curated App Store. The result is a web dominated by a few huge gatekeepers. SEO is life or death because Google is the only way for a website to be “real” for people. And most techies went along with it because they shared the vested interest, or did not appreciate the existing system that creates the real life shopping experience we see every day. And so where are we today? A new generation of techies trying to use the power of encryption to create a decentralized web. Web3.
- Sytten 5y agoEV have their place in the ecosystem, they are just useless for websites. You still need them to properly sign binaries for Windows or get your logo showing in Gmail (BIMI), which are legit usecases where you want to verify the identity of the company. The alternative to that is each business setup their own verification mechanism similar to what Apple does and you have to pay each one a good chunk of money. (Arguably the EV certs are not cheap either).
- bombcar 5y agoHow does that help (much) in the case where some rando can get an EV for "Stripe, Inc." The idea behind EV was almost a good one - but you'd need a central authority that can say "This Nissan is the Nissan you're expecting" which is nearly an impossible problem at scale (see https://nissan.com https://nissan.com vs https://www.nissanusa.com https://www.nissanusa.com). What has happened is Google is the central authority for 90% of the web - you search the company and click the link (which maybe is an ad to a scam site?).
- zuzun 5y agoI don't see what's fundamentally wrong with EV certificates, as long as the certificate authorities do the proper verification. The certificates contain more than just the business name, so I think the criticism should be directed towards browsers that hide the relevant information behind 5 clicks.
- blurker 5y agoWhat about the Stripe Inc. example? That example alone is a pretty big nail in the coffin for EV in my opinion. Not to mention all the usability problems that user studies have found which render it effectively useless. It's not just the number of clicks either. What about how the corporate names don't match the TLD's? What about conglomerates that have all sorts of entity names? What about misspellings of corporate names, just like misspellings of TLD's?
- snowwrestler 5y agoThe Stripe.com example is widely misunderstood, even by the person who did it. It doesn’t matter that it was a name collision with Stripe the payment processor. EVs were not designed to resolve name collisions. They were not even intended to attest that a business is legitimate. What matters is that Ian had to register a company to get that EV. Which means that if he had actually tried to scam people with it, the police would have a nice paper trail back to him. The paper trail is the deterrent. All the EV does is attest to the existence of a paper trail. Name collisions are not a problem in general. There are other people in the U.S with the same first and last name as me. There are thousands of restaurants called “McDonalds” that all look the same even though they are owned by different companies. It’s a solved problem. It is solved with legal documentation, like taxpayer ID numbers, articles of incorporation and payment records. The sole purpose of EV and OV certs is to cryptographically connect your browser to those.
- blurker 5y agoyeah, about that paper work... 1. The paper trail is probably not as good as you think. I feel like you're thinking of a US system where there might be some pretty solid systems in place, but what about all the other countries around the world? I'm sure there will be at least a few places that will not be great paper trails. 2. The paper trail only helps you after you've been scammed as a way to maybe track down whoever did that. A costly and time consuming process which may be next to impossible if you think about the complications of shell companies and legal jurisdictions. Or are you suggesting that before you use a site you go through all this work proactively?
- blurker 5y agoI feel like a lot of commenters may not have watched the video of Emily Schecter's that was linked in the article. IMO it actually did a better job of explaining the problem with EV's than the author's post did. Or at least it was very complementary. There are a lot of flaws in EV. I think the biggest one I saw was that it is effectively no more useful than TLD's/subdomains. In fact, it's worse, because unlike domains, there can be multiple owners of the same corporate name! To the people saying there is a paper trail... What good is that? There are "paper trails" for domain registration too. But that isn't very reliable and the same would happen with corporate registration. We know this all too well from how wealthy people use shell corporations to hide. And I'm sure there will be plenty of places around the world where it will be easy to incorporate for bad actors, even if some places do a good job of creating a paper trail. Fundamentally, this is a hard problem to solve and I really don't see EV solving this any better than domains.
- Sander_Marechal 5y agoI thought that the ideas behind that video are terrible. Google and Chrome are working tirelessly to do away with the URL for some nefarious reason. I bet it has something to do with ramming down AMP down everyone's throat. Do away with the URL and people can't tell they're on Google's cached copy instead of the original site.
- blurker 5y agoCan you elaborate specifically which ideas you thought were terrible and why? fwiw, I am not the biggest fan of Google's level of control either, but I think that the ideas in the video stand for themself. Forget the Chrome-specific stuff and just focus on the basic UX concepts. Without providing some specifics, your comment comes across as pretty shallow and more about your dislike of Google than criticism of the actual ideas. Here are some of the ideas that I think stand on their own regardless of who presented them: - EV's cannot be trusted by users because different entities can have the same name, how is the user going to vet that? - EV's have a problem of corporate name != domain name, how is the average user going to figure out if it's the right entity? - Domains are difficult for users to verify because there are so many permutations possible with all the new TLD's, as well as subdomains - URL's are difficult to read because paths are often non-human readable - URL's are hard to share through non-digital means and more... lots of generally applicable stuff that isn't all a giant Google conspiracy. What is terrible about these ideas?
- 300 5y agoThe problem is real and it's not the only one in this space. I was surprised to see so many words and so little substance. If feels like Troy didn't really try about this one.
- outloudvi 5y agoI guess the same idea also applies to QWAC. https://www.eff.org/deeplinks/2022/02/what-duck-why-eu-proposal-require-qwacs-will-hurt-internet-security https://www.eff.org/deeplinks/2022/02/what-duck-why-eu-propo...
- ryan29 5y agoOV certificates are even worse. The verification is a hassle and it's extremely difficult to distinguish OV from DV. Try to figure it out. The only way I'm aware of is to make sure the `Policy Identifier` [1] of the certificate is `2.23.140.1.2.2`. I've also never had a good experience with the validation process from any of the CAs. They often push anything that's not immediately discoverable back to the applicant and expect them to do the leg work. I've had both Comodo and DigiCert do this to me in the past. Here's an example from DigiCert. This happened this year (2022). > First, As part of the verification process, we are required to confirm the registration of your organization with the local registering authority. > We have attempted to locate the registration records using online resources, however we have not been able to locate such a document. If you are aware of any government based search tools for your jurisdiction that can be used to locate proof of the organization's registration, please reply to this email with a link and instructions for locating that record. Once received, our validation team will confirm the record and proceed with the validation process. Really? To me that seems like someone who isn't familiar with my jurisdiction because they don't know the process. What's stopping me from sending them a link to a fake, official looking site? It seems like an invitation for social engineering. Code signing certificates are the same. It's infuriating. In my experience, they look for your company on Google Local (or whatever it's called now) or similar and if they can't find it they punt it back to you. I think the whole process is worse than nothing because it's selling a false sense of security for anyone who believes the marketing. From a customer value standpoint, I'd rather pay for a DV certificate where the value comes from helping me to set up proper CAA records to prevent mis-issuance as well as certificate monitoring for any potential lookalike domains. Of course, the margins on that probably wouldn't be as good. Thankfully I only deal with one place that insists on buying expensive certificates because "they're better". Just for fun sometime go look at the TLS certificates used by all of your local government websites and try to figure out what they cost. Then factor in the labor for multiple people to coordinate annual renewals and manual installation. It's frustrating. 1. PDF Warning: https://cabforum.org/wp-content/uploads/CA-Browser-Forum-BR-1.8.1.pdf https://cabforum.org/wp-content/uploads/CA-Browser-Forum-BR-...
- brightball 5y agoI need to dig it up, but PayPal once did a security presentation on “trust indicators” like EV certs related to user behavior. The conclusion was essentially that trust indicators offer no benefit at all and can even go as far as creating harm since it could encourage a user to trust an entity that they don’t know if the system is abused. The psychology of it boils down to this: people trust lots of sites, services and other people who haven’t paid extra for these trust indicators and because of that it’s not going to change their behavior at all. On the flip side, inline and accurate warning indicators go a long way towards making users more cautious. Big red warnings from Google about users outside your domain for example.
- billpg 5y ago"Nobody Looks Beyond the Lock" I did. A high-value (to me) service used a cert with the green banner and I'd look to it to be reassured I was in the right place. Then one day, it disappeared. Alarm bells started ringing and I tried to find out what was going on. I called their help desk and asked if they had changed their TLS certificate but the helper I spoke to had no idea what I was talking about and couldn't be persuaded to escalate my query. Just in case my connection was being hacked by someone who managed to register a lesser TLS certificate, I left it a day until I could try again from my home broadband. In the end, I did go ahead and use the site without the green banner, which makes me my own worse enemy.
- mananaysiempre 5y agoBrowsers stopped showing the banner a couple of years ago[1-3], around the time of the Ian Carroll’s Stripe, Inc. of Kentucky demonstration[4]; maybe that was it? It caused a great outcry from CAs, and I would’ve normally been against a single-sided, mostly Google-driven change like this, but the discussion[5] shows, at least as I read it, that CAs are unwilling to clearly communicate that the EV “green bar” does not imply “trustworthy”, it just upgrades “you have been securely connected to satan.com”, an authenticated DNS name, to “you have been securely connected to Satan LLC”, an authenticated legal-entity name. And as Stripe, Inc., of Kentucky shows, it’s not clear this is an upgrade at all, because while the rules for domain uniqueness in the DNS are relatively (barring IDNA) straightforward and well-known, the rules for uniqueness for names of legal entities are complex and dependent on jurisdiction to such an extent that neither users nor even CAs can be reasonably expected to follow them all. (I think one discussion on the CA/Browser Forum list mentioned that—forget state-scoped legal names in the US Stripe case—Germany has township-scoped legal names, so jurisdictionOfIncorporation would literally have to record, and UAs to show, the address of a specific town hall in Germany. Sure you know which one it should be?) Even today you will find CA websites[6-8] proudly proclaiming “customers think the EV green bar means trustworthy” (and, presumably, if they don’t, you should teach them to). Except it doesn’t, and believing it does is harmful for users, so into the dustbin of history it goes. (Of course, the conventional legal system is not completely clueless about this namespace issue and in most countries implements “field of endeavour”-scoped trademarks as a solution, but the issue of jurisdiction on a global Internet, as opposed to a billboard in your hometown, is only somewhat attenuated, and the discussion seems to show CAs were unwilling to move away from “green bar = secure” marketing, which is harmful however you spin it.) There’s a more general line of research on the uselessness of positive security indicators, that first entered the public eye perhaps with Moxie Marlinspike’s green-padlock-favicon demonstration[9] at Black Hat 2009. The Google announcement page[1] links to some later developments in that respect. Chrome later phased out “secure” for HTTPS sites completely in favour of showing “not secure” for HTTP ones, highlighted in red once a password input or similar appears[10]. Fortunately for you if you want your EV TLS certs back, the corpse seems to be in the process of being raised[11,12] through the necromantic power of money and government coercion. (What is it about PKI that drives everywhere bureaucrats so wild?..) [1] https://chromium.googlesource.com/chromium/src/+/HEAD/docs/security/ev-to-page-info.md https://chromium.googlesource.com/chromium/src/+/HEAD/docs/s... [2] https://bugzilla.mozilla.org/show_bug.cgi?id=1572936 https://bugzilla.mozilla.org/show_bug.cgi?id=1572936 [3] https://www.troyhunt.com/extended-validation-certificates-are-really-really-dead/ https://www.troyhunt.com/extended-validation-certificates-ar... [4] https://arstechnica.com/information-technology/2017/12/nope-this-isnt-the-https-validated-stripe-website-you-think-it-is/ https://arstechnica.com/information-technology/2017/12/nope-... [5] https://groups.google.com/g/mozilla.dev.security.policy/c/iVCahTyZ7aw/m/ysfOGRFBEwAJ https://groups.google.com/g/mozilla.dev.security.policy/c/iV... [6] https://www.digicert.com/faq/when-to-use-ev-ssl.htm https://www.digicert.com/faq/when-to-use-ev-ssl.htm [7] https://www.globalsign.com/en/blog/why-ev-ssl-is-here-to-stay https://www.globalsign.com/en/blog/why-ev-ssl-is-here-to-sta... [8] https://www.thesslstore.com/new-to-ssl/is-ev-worth-it.aspx https://www.thesslstore.com/new-to-ssl/is-ev-worth-it.aspx [9] https://vimeo.com/50018478 https://vimeo.com/50018478, slides at https://www.blackhat.com/presentations/bh-dc-09/Marlinspike/BlackHat-DC-09-Marlinspike-Defeating-SSL.pdf https://www.blackhat.com/presentations/bh-dc-09/Marlinspike/... [10] https://security.googleblog.com/2018/02/a-secure-web-is-here-to-stay.html https://security.googleblog.com/2018/02/a-secure-web-is-here... [11] https://scotthelme.co.uk/looks-like-a-duck-swims-like-a-duck-qwacs-like-a-duck-probably-an-ev-certifiacate/ https://scotthelme.co.uk/looks-like-a-duck-swims-like-a-duck... [12] https://www.eff.org/deeplinks/2022/02/what-duck-why-eu-proposal-require-qwacs-will-hurt-internet-security https://www.eff.org/deeplinks/2022/02/what-duck-why-eu-propo...
- bell-cot 5y agoBluntly put, SSL Certificates exist (or at least are widely promoted and used in their current form) to protect the business models of a few very large corporations. Especially against parties like sleazy ISP's, who might love to (say) replace all the Google Ads on web pages which their customers view with new ads sold by the ISP. Beyond that, it's all FUD, marketing, and hype. And at least 90% of any actual benefits to normal users of the web fall under "convenient side-effect of what the large corporations would have done anyway, for their own benefit". [/cynic]
- zokier 5y agoSure, ev certs might not be all that great, but I do find Troys long-running crusade against them weird. I mean, it feels pretty disproportionate, like does anyone care that some corpos end up paying few hundred bucks extra for their certs or whatever? Isn't there almost endless amount of more important issues in the security landscape?
- CrendKing 5y agoProbably explained in the very first sentence of the post: "I have a vehement dislike for misleading advertising." Human somethings do things driven by their emotion, even if the thing is not the most logical or profitable decision.
- SAI_Peregrinus 5y agoIt's fraudulent activity (false advertising) by some of those very agencies who are trusted to authenticate certificates! CAs selling EV certs is fine. CAs advertising EV certs as providing a meaningful benefit to customers is NOT fine, it's an abuse of their trusted position.
- y-c-o-m-b 5y ago> nobody is actually going to look beyond the lock anyway. (Yes, I know there'll be someone somewhere who eventually does, let's just agree that "nobody" is a number that rounds to 0%.) I mean seriously, do you ever do this? Yes, yes I do... did. I'm in the US and get a vast array of bills coming from all kinds of different sources (utilities, doctors, etc.) that manage their payments via some random portal. Some of the "payment portals" they send me to are sketchy as hell and it brings me great anxiety to use them even though it's guarantees my payment arrives on time and I don't have to fuss with snail mail (and its associated thefts). I always make sure they are https and I used to look "beyond the lock" to make sure they a well-known CA was being used. Well as Troy mentions, it's effectively a worthless endeavor. I'm glad he's bringing this topic up to gain more visibility and awareness towards the issue.
- bombcar 5y agoThis is a huge problem - legitimate sites are getting names that look damn scammy - even "www.securebillpay.net" starts to look suspicious and they get way worse. If the companies aren't going to bother there's no hope for the users.
- jimmygrapes 5y agoccbill.net is the one I've always been the most skeptical about, since I associate it with age verification things decades ago for certain sites that were not serviced by other payment providers
- nixpulvis 5y agoThe arguement that 'Nobody Looks "Beyond the Lock"' is not really valid in my opinion. If even 0.001% look, there's a chance someone will blow the whistle on a sketchy operation. Not to mention that I might only look closely on some responses. The other issues with EVs are more damning to me.
- bruce511 5y agoThe counterpoint to that is that I'm not spending money, and substantial amounts of hassle, to buy an EV to increase my customer base by 0.001%. Im not sketchy, my site isn't sketchy, and so there's nothing for the 0.001% to complain about. So my site is DV, always has been, and no one has ever complained about that. So the money, and more importantly the hassle has no benefit to me. Rinse and repeat for (some large % of web sites), users don't care about green bars or not, and EVs become useless.
- panny 5y agoSays the site being MITM by cloudflare. Not that he's wrong, but glass houses...
- Animats 5y agoI built Sitetruth.com to try to solve that problem. I'm going to shut it down soon. The goal of SiteTruth was to try to find the real-world business behind a web site, and look up information about the business, such as how long it has been in business and its annual revenue. That's become harder and harder over the last decade. First, it's now acceptable to have an online business with no real-world address and no visible legal existence. This is illegal in the European Union and illegal in California if the business accepts payments, but enforcement is nonexistent. Second, more sites have become inaccessible to scraping by servers. I have a system which looks for a human-readable business address on a site. It looks in the obvious places (front page, "about", "legal", "terms", "contact", etc.) and quits after trying the 20 most likely pages. It uses a honest agent ID ("Sitetruth.com site verification system", registered with the now meaningless "bots vs browsers" list) and obeys robots.txt. A sizeable fraction of the time, it can't read the site at all. Third, the data sources for company information have been becoming less accessible. There used to be two reliable data sources: Hoovers, and Dun and Bradstreet. They merged. Dun and Bradstreet for a while became rather corrupt. They licensed a company in Santa Monica, CA to use their name, and sent the small-business part of the business to them. This unit's marketing approach was "Nice credit rating. Be a shame if it something happened to it". After much litigation, DnB HQ bought the Santa Monica company, but the reputational damage was done and DnB is no longer the gold standard of company information. There are lower tier data sources (look up "US Business List"), but the data quality is poor. Anything based on user recommendations, like Yelp, gets spammed, so that's out. Yahoo Directory, which was reasonably spam free, is gone. Fourth, the SSL cert industry became corrupt. OV standards were never very high, and EV standards started slipping. Then there was the Cloudflare problem. Cloudflare is a certificate authority, and they issue certs to themself for domains which run through Cloudflare. So looking up a cert just gets Cloudflare's info. Fifth, Google is making it harder and harder to have Chrome plug-ins that critique their ads. I dropped Chrome support recently, and only have a Firefox add-on at this point. So, after fifteen years, Sitetruth is coming to an end.
- ttyp3 5y agoYes, it's difficult to even determine in which _state_ a (US) business is operating now.
- tgbugs 5y agoI've been coming around to the idea that the threat models that are often used for website identity are not the ones we want. The ssh threat model related to changes in host keys seems to me to be a better one. The first time you connect to a website you get whatever identity it wants to show you. Whether it is a real site or not doesn't particularly matter, it only matters when the identity changes. If my first access was MITMed and then I connect to the "real" site, I should go and check to see what information changed, and if I sent any sensitive information I should probably do something to mitigate that (the exact action would depend on the exact type of info you sent). In the reverse case where you trust the original identity more than a changed identity you would ignore the event and might possibly want to inform the original entity that someone is trying to impersonate them. Still fairly complicated for the original user, but certificate expiration would no longer be the insanity that it is now, and you can at least get transport security without the big scary self signed warnings that show up now.
- notriddle 5y agoSSH's model isn't very good, either. You can be MITM'ed for free the first time you connect (obviously, that's what TOFU means), and server identities are tied either to network addresses or to domain names, neither of which are permanent. Tor Hidden Services are closer to a well-designed petname system. The important insight is that, since domain names are too technical for ordinary people anyway, they might as well just be random numbers. If you trust someone to give you the real domain name for the server, you can also trust them to give you a signature for their real public key, and you don't even need a CA any more. The advantage of using a cryptographic signature for your address is that it implicitly forms a web of trust, using the links that people were already sharing. The biggest problem with this — and SSH doesn't seem to do a better job of it than Tor does — is key rotation. Deprecating an old cryptographic algorithm is a total disaster in any system that doesn't support key rotation — it's fine on the server side (just host with both keys, and serve a 301 redirect from the old one to the new one), but the client side eventually needs to stop supporting the old algo, because those would be vulnerable to downgrade attacks, and at that point you cut off anyone who hasn't switched to the new one yet. CA's take care of this, because it's literally their job, but distributing the responsibility to everyone can easily mean it doesn't get taken care of properly.
- throwaway984393 5y agoThe funniest thing to me was always how any non-EV cert can be used in place of an EV cert if you want to MITM. Just find a way to generate a non-EV cert for a domain (from any of the hundreds of CAs) and go ahead and intercept traffic. Nobody will notice that the domain no longer uses an EV cert. The browser won't care. So it's not actually providing any security at all. I blame the browsers. They could have made it perform some kind of check, give some kind of warning. We've had to drag them kicking and screaming to adopt every ridiculous security extension to the web. They still use half-ass measures like HSTS that are trivial to work around. Nobody look at the big pink elephant.
- zaptheimpaler 5y agoRight now, if what Troy is saying is true, then self-signed certificates are basically every bit as good as a LE cert - because no one actually verifies the chain of authority. But oh no, self-signing is a bad practice, and effectively useless because browsers will throw up warnings. So you go to LetsEncrypt and get a certificate that has a pretty green padlock.. because their `certbot` made it with 0 review of who you are or what the site does? How is this different at all? I'm not an expert, but at high level it seems to me that the only way to get trust is to tie every digital property to a real person, do some sort of KYC on them and allow for dispute resolution. The usual bureaucratic pains of doing anything in the real world would extend to the digital world, and the usual arguments about increase in regulation entrenching existing power structures and slowing innovation apply.
- xg15 5y ago> because their `certbot` made it with 0 review of who you are or what the site does? How is this different at all? I think it only makes sense if you view the whole HTTPS everywhere initiative as a counter against MITM attacks - and only that. Everything related to identity has effectively been delegated to domain registrars. TLS certs as envisioned by browsers are really only about proving that you have genuine control of a particular domain - they give no indication at all who you are, whether your intentions are good or whether or not you're trying to imitate a different domain. In that sense, the UI redesign from "neutral/secure" to "insecure/neutral" in Chrome makes some sense: HTTPS is necessary but not sufficient to make a site trustworthy: A https site might still be a scammer, but a http site can always be intercepted and manipulated by MITM, so http sites can can never be trustworthy at all.
- zaptheimpaler 5y agoYes, SSL prevents MITM but my point was that a self-signed certificate does this just as well as an automated certificate from LetsEncrypt.
- xg15 5y agoIt doesn't though. The attacker could simply present their own self-signed certificate - and there'd be no reliable way to determine which certificate is the right one. You could mitigate this with some kind of (non-scary) trust-on-first-use UI. But even that doesn't help you if you're unlucky enough to encounter the attacker before the real site. (Which isn't even that unlikely if the attacker is e.g. an ISP proxying all connections by default) What LE gives you is a signed statement saying in effect: "we've seen that the owner of this cert can make changes to the domain which are visible from multiple different network locations - so they are very likely the real owner of the domain and not a MITM". That's valuable, even if it doesn't tell you anything about who that entity is. What I absolutely would wish for is some mechanism to include a cert hash in the URL. Then you could e.g. distribute QR codes with the cert hash embedded and circumvent the trust problem that way. Then, I agree, there would be no reason not to use self-signed certificates with that technique.