3 ms·
that’s not what he meant, and you know it. he means use the OS store (the one the user has control over), instead of having each app do its own thing (where th
by hello_computer 2y ago
that’s not what he meant, and you know it. he means use the OS store (the one the user has control over), instead of having each app do its own thing (where the user may or may not have control, and even if he does have it, now has to tweak settings in a dozen places instead of one). they try to pull the same mess with DNS (i.e. Mozilla’s DoH implementation)
- tptacek 2y agoI don't understand, because the user has control over the browser store too. (As an erstwhile pentester, btw, fuck the OS certificate store; makes testing sites a colossal pain).
- hello_computer 2y ago> I don't understand, because the user has control over the browser store too. i already mentioned that ("may or may not"). former or latter, per-app CA management is an abomination from security and administrative perspectives. from the security perspective, abandonware (i.e. months old software at the rate things change in this business) will become effectively "bricked" by out-of-date CAs and out-of-date revocation lists, forcing the users to either migrate (more $$$), roll with broken TLS, or even bypass it entirely (more likely); from the administrative perspective, IT admins and devops guys will have to wrangle each application individually. it raises the hurdle from "keep your OS up-to-date" to "keep all of your applications up-to-date". > As an erstwhile pentester exactly. you're trying to get in. per-app config makes your life easier. as an erstwhile server-herder, i prefer the os store, which makes it easier for me to ensure everything is up-to-date, manage which 3rd-party CAs i trust & which i don't, and cut 3rd-parties out-of-the-loop entirely for in-house-only applications (protected by my own CA).
- tptacek 2y agoIt's baffling to me that anyone would expect browsers to make root store decisions optimized for server-herders. You're not their userbase!
- hello_computer 2y agoneither are pentesters
- tptacek 2y agoRight, I don't think the pentester use case here is at all dispositive; in fact, it's approximately as meaningful as the server-herders.
- mwcampbell 2y ago> (As an erstwhile pentester, btw, fuck the OS certificate store; makes testing sites a colossal pain) Can you please explain? I'm just curious, not arguing.
- tptacek 2y agoIt's a good question! When you're testing websites, you've generally got a browser set up with a fake root cert so you can bypass TLS. In that situation, you want one of your browsers to have a different configuration than your daily driver.