5 ms·
I liked the CA MITM call out.. we just trust these organizations to not deploy wildcard malicious certificates. Kinda messed up devices come preloaded with unc
by collsni 3y ago
I liked the CA MITM call out.. we just trust these organizations to not deploy wildcard malicious certificates.
Kinda messed up devices come preloaded with unchangeable trusted CAs
Guy knows his stuff, also works for dod.
- yjftsjthsd-h 3y ago> we just trust these organizations to not deploy wildcard malicious certificates. Don't we have transparency logs to check that now?
- judge2020 3y agoYes, Chrome and Safari will not load a site if the cert is not in CT. https://no-sct.badssl.com/ https://no-sct.badssl.com/
- sedatk 3y agoalso Edge. It's an open issue on Firefox: https://bugzilla.mozilla.org/show_bug.cgi?id=1281469 https://bugzilla.mozilla.org/show_bug.cgi?id=1281469
- ignoramous 3y agoWow. Firefox should really prioritize this if all major browsers are doing it already.
- sedatk 3y agoThere is a theory which states that if ever anyone discovers exactly which decade old bug should be fixed in Firefox, it will instantly disappear and be replaced by some obscure web service by Mozilla Foundation. There is another theory which states that this has already happened. (in memory of Douglas Adams)
- RunSet 3y agoLet's test that theory: It's this one. https://bugzilla.mozilla.org/show_bug.cgi?id=505521 https://bugzilla.mozilla.org/show_bug.cgi?id=505521
- sedatk 3y agoIntroducing RunSet™ by Mozilla Foundation: an installation customizer for Mozilla suite of software. Just visit mozilla.org/runset, click on what pieces of software you want, and a custom installer is generated just for you. You can even embed your profile picture to the installer to share it with your friends and family. Fully customizable, fully free. RunSet™: Install everything everywhere all at once. [Donate]
- andreasha 3y agoBut not Brave apparently
- trishmapow2 3y agoLooks like it's in the beta https://github.com/brave/brave-browser/issues/22482 https://github.com/brave/brave-browser/issues/22482.
- AndyMcConachie 3y agoThey will not load the site if the certificate does not have embedded SCTs. That's different. They don't actually go check and compare the embedded SCT with what is in the logs. It would be incredibly slow to load the site if they did that.
- Maxious 3y agoThis is going to blow your mind but they do, it's called the Inclusion Checking phase https://docs.google.com/document/d/1FP5J5Sfsg0OR9P4YT0q1dM02iavhi8ix1mZlZe_z-ls/edit https://docs.google.com/document/d/1FP5J5Sfsg0OR9P4YT0q1dM02...
- AndyMcConachie 3y agoSo now we trust them to log it. What's the difference?
- ZiiS 3y agoIf someone else logs a certificate for one of my domains I am notified and can have it revoked.
- vladvasiliu 3y agoHow are you following this in practice, especially if every service has its own certificate that it rotates every two months via letsencrypt or similar? It's not clear to me how you know who asked for the certificate in the log. Do you somehow compile the private keys of all entities that are allowed to request certificates and compare that to the CTL?
- ZiiS 3y agoI only have about a two dozen certs so having a notification a week is managable not had to think how to scale it.