6 ms·
Browser makers should ban any root CA using MD5 very, very soon.
by ambition 18y ago
Browser makers should ban any root CA using MD5 very, very soon.
- geekamongus 18y agoAnd root CA's should stop using MD5 even sooner.
- wyday 18y agoAnd all the customers that bought certificates from these CA's? Let 'em hang? Who cares that these customers business reputations depends on the SSL certificates validity. I agree with you that certificates made with the MD5 hash should be phased out gradually by the CAs, but you can't just do a sweeping revocation without ruining businesses.
- cperciva 18y agoWhich would you prefer to have: Customers complaining that your SSL certificate is invalid until you spend the a few minutes to get an updated certificate; or customers complaining that you're a fraud because they gave you (well, really just someone pretending to be you) money and you haven't delivered the product/service they ordered?
- wyday 18y ago> Customers complaining that your SSL certificate is invalid Most customers will shrug their shoulders and try another site that doesn't throw a scary warning. Normal people don't report bugs. > customers complaining that you're a fraud You're right, this is a real problem. But blocking certificates outright isn't less of a problem.
- tptacek 18y agoI don't understand your logic. Revoking certificates will cause unpleasant SSL errors. Not revoking certificates will negate all the security of SSL. How could those two problems be comparable?
- wyday 18y ago> Revoking certificates will cause unpleasant SSL errors. Unpleasant errors scares away buyers. That is, Error + Credit Card = No Purchase > Not revoking certificates will negate all the security of SSL. Not true. The encryption part of the certificate is still there. However, the added assurance that you're really on the site you think is compromised. But has the assurance part of SSL certificates actually reduced phishing? Stupid people will still put all their money in BankOfShmamerica.com as long as it looks sort of like the BankOfAmerica.com site and doesn't throw any errors.
- tptacek 18y agoIf you think "the encryption part of the certificate" is still there, you don't really understand how SSL works. Without a secure certificate, you can't trust your SSL session keys. See: http://news.ycombinator.com/item?id=277284 http://news.ycombinator.com/item?id=277284
- modoc 18y ago"the encryption part of the certificate" is still there as far as the wifi packets leaving your laptop are concerned, and as far as the poorly/maliciously configured linux router in the backroom of the coffee shop are concerned. So, is it 100% secure? No. Is there still a reasonably high barrier of entry to getting your CC number/bank login? Yes. That's like saying if you were using one of the weak Debian ssh keys, you might as well be using telnet. It's simply not true. The effort to steal your info is at least an order of magnitude (if not more) higher, even with weak ssh keys. The same situation applies here.
- tptacek 18y agoYou made the same point a few minutes ago, and I replied to it; long story short, you're not correct.
- nailer 18y agotptakec is 100% correct, but I like to explain stuff to people: The packets leaving your laptop are protected from being eavesdropped by third parties, but the party you're sending your banking password to is some asshole who now apparently runs a CA, and just issued a certificate telling your web browser he's your bank.
- stcredzero 18y agoThe customers that bought certificates should be getting an SHA1 certificate from the CAs. Why shouldn't there be a sweeping revocation? Any web apps that are dependent on rapid response to problems like this will be able to respond quickly. If things are handled properly, we should see abandonment of MD5 certs in a matter of days. Taking more time just gives time to the exploiters.
- fhars 18y agoA sweeping revocation wouldn't work, as you can only revoke certifcates that have not been tampered with. You must issue a SHA-1 certificate to everyone and then change every piece of software that uses certificates not to trust certificates with an MD5 hash in the trust chain. If someone else has successfully performed this attack, he might posses a CA certificate that is valid until 2038 and you have no way to know about it until he uses it against you.
- nailer 18y agoI'd suggest browsers, via an update, stop accepting certificates using known vulnerable hashing routines.