5 ms·
woah at least a DOS with just a malicious email address and potentially an RCE. yiiiiiikes that's bad
by cp9 4y ago
woah at least a DOS with just a malicious email address and potentially an RCE. yiiiiiikes that's bad
- tialaramex 4y agoFrom what I am reading the address needs to be in a certificate you trust. So, then the question is, who is issuing certificates some lunatic wrote nonsense into, but which you trust? In many cases the answer will be "Nobody".
- rtev 4y agoYeah, I was expecting heartbleed and this is “denial of service if you manage to sneak a malformed certificate by a CA and it makes into an attack chain”. Other than the sheer number of devices vulnerable, I don’t see this as being that big a deal.
- thephyber 4y agoI would approach the issue rom the opposite direction. What is the minimum failure of any CA required for me to get popped? If some malicious actor goes through the effort to get me, how many other clients/servers on the internet can get from the same CA breach / malicious cert? How would you know to un-trust a CA you already trust until after the incident (a malicious certificate issued) had already happened? Even if the incident happened, someone still needs to alert you to un-trust the CA involved. That takes time. History of mistakes / bad decisions by cert authorities: https://sslmate.com/resources/certificate_authority_failures https://sslmate.com/resources/certificate_authority_failures > who is issuing certificates some lunatic wrote nonsense into, but which you trust Do you know every CA your OS and each browser trusts out of the box? Have you done an audit of each one of them? Does an audit 100% prevent a breach from happening in the future? What are the odds that their policies are perfectly followed every time and that no employee in the right place can be bribed/blackmailed? Remember Cert Authorities are watering holes. Almost all of the internet trusts a few of them. By breaching one (which may be very significant, either technically or reputationally), the payoff can be massive.
- tialaramex 4y ago> What is the minimum failure of any CA required for me to get popped? They need to issue an intermediate with this weird constraint, for most CAs that's a major business decision, maybe bringing in auditors to witness the ceremony, and then it's advertised, which seems like we'd go "Er, why does it have this really strange constraint" and the jig is up. > Do you know every CA your OS and each browser trusts out of the box? Yes. > Have you done an audit of each one of them? Does an audit 100% prevent a breach from happening in the future? No, I have not performed an audit of any public CAs. My observation, over years more and less actively overseeing the Web PKI (sometimes as a contributor to m.s.d.policy) is that the CAs are on the whole not malevolent but they're sometimes incompetent and lazy, like most humans. I think you're imagining this is an end entity certificate needed, but the end entity certificate isn't interesting here, OpenSSL is (mis)parsing data from an intermediate, the end entity certificate is just a trigger and not an interesting one. I don't see any way you could get such a "trigger" certificate from Let's Encrypt, but I wouldn't expect it's hard to buy something suitable from a for-profit CA, however the problem is that there's no malformed intermediate to act as the explosive for you to detonate.