5 ms·
Never think HTTPS will save you from proxies built by attackers... This may make it much simpler...
by SebFender 2y ago
Never think HTTPS will save you from proxies built by attackers... This may make it much simpler...
- SteveNuts 2y agoWouldn’t there still need to be a major vulnerability with the TLS library your client is using?
- supriyo-biswas 2y agoYou can obtain a certificate for the domain in question (easier if you are a nation-state) and MITM that specific user.
- theamk 2y ago... but you need to MITM server to obtain certificate, and if you can MITM server, why bother with user's wifi?
- supriyo-biswas 2y agoBecause it’s easier that the server be MITMed for a shorter duration to prevent discovery[1]. It’s also easier if you can just strong arm the CA to issue a certificate or have the shady CA issue it[2][3]. [1] http://notes.valdikss.org.ru/jabber.ru-mitm/ http://notes.valdikss.org.ru/jabber.ru-mitm/ [2] https://www.wired.com/2010/03/packet-forensics/ https://www.wired.com/2010/03/packet-forensics/ [3] https://bugzilla.mozilla.org/show_bug.cgi?id=1391063 https://bugzilla.mozilla.org/show_bug.cgi?id=1391063
- yjftsjthsd-h 2y agoHow does one bypass certificate transparency? I tend to exclude state actors from my threat models (1. they tend to be the all-powerful boogeyman that bypasses all threat models anyways, and 2. I doubt that the NSA is going to get you by way of coffee shop wifi) but I'm actually struggling to see how even they would bypass this particular protection; if Chrome only trusts CT-logged certs, even a targeted one-off is likely to be discovered (albeit, AIUI, after the fact).
- theamk 2y agoSure they will, given Chrome's requirement for CT logs, any attacker-issued certificates will be logged, someone will find the suspicious record, and the method will likely be burned from all the publicity. I have no doubt that there maybe a few dozen people in the entire world who would get attacked this way, but the chances it would be me are pretty much zero.
- 8organicbits 2y agoHow often are you reviewing the CT logs for your domains? I posit that's rare.
- immibis 2y agoBTW this attack actually happened with jabber.ru - "law" "enforcement" physically intercepted their Ethernet port, then they got to use their IP address and could issue new certificates.
- debatem1 2y agoDo you happen to have a link or any other information about this?
- immibis 2y agohttps://notes.valdikss.org.ru/jabber.ru-mitm/ https://notes.valdikss.org.ru/jabber.ru-mitm/ https://news.ycombinator.com/item?id=37961166 https://news.ycombinator.com/item?id=37961166
- 8organicbits 2y agoRare was intended to refer to "the monitoring of CT logs". The CA system doesn't protect against an adversary who has physical control of your system.