3 ms·
> I'm not as convinced as the author is that nation states can easily tamper with certificates these days. I am not sure how much CT checking we do before each
by throw_a_grenade 1y ago
> I'm not as convinced as the author is that nation states can easily tamper with certificates these days. I am not sure how much CT checking we do before each page load [...]
They can MITM the connection between the host and LE (or any other CA resolver, ACME or non-ACME, doesn't matter). This was demonstrated by the attack against jabber.ru, at the time hosted in OVH. I recommend reading the writeup by the admin (second link from the top in TFA).
This worked, because no-one checked CT.
- fragmede 1y agoLE checks from multiple places, so you'd have to MITM all of them, which makes it seem rather challenging to actually pull off.
- Ajedi32 1y agoAFAIK that's not a required feature of the DV process, and even if it were it wouldn't help if the MITM was happening between the website and the wider internet. That said, I don't think there's a way to stop a nation state from seizing control of a domain they control the TLD name servers for without something like Namecoin where the whole DNS system is redesigned to be self-sovereign.
- tialaramex 1y agoMulti-perspective is or will be (I didn't pay attention to the timeline) required by the Baseline Requirements which are effectively the rules for how Web PKI certs work. The system is tamper evident not tamper proof. A nation state adversary can indeed impersonate my web site and obtain a new certificate, but the Web Browser doesn't trust that certificate without seeing Proof it was in the CT logs. So, now the nation state adversary need Proof it was Logged. Whoever issued them the proof has 24 hours to include that dodgy certificate in their public logs for everyone to see. If they lie and don't actually log it, the proof will be worthless and if shown to a trust root this bad proof will result in distrust of the log's operator. That's likely a six or seven figure investment thrown away, for each time this happens. On the other hand if they do log it, everybody can see what was issued and when, which is inconvenient if you'd prefer to be subtle like the NSA and to some extent Mossad. If you're happy to advertise that you're the bad guys, like the Russians and North Koreans, you do have the small problem that of course nobody trusts you, so, you can't expect any co-operation from the other actors...
- Ajedi32 1y agoYes, CT makes any sort of certificate issuance attack relatively "loud", but as you seem to be aware that doesn't actually stop the attack from happening in the first place unless the attacker cares about keeping it a secret. This isn't like a missisuance where you can blame the CA and remove them from the root stores; they'd just be following the normal domain validation processes prescribed in the BRs.
- tialaramex 1y agoThe loudness means that when people yell "The government are doing X" you can go see for yourself, are they doing X? No? So what was the yelling about? Going to Portland to check whether it's on fire would be a lot of effort - so to some extent I must take it on trust that it's not actually on fire despite Donald Trump's statement - whereas visiting crt.sh to check for the extra certificates somebody claims the US government issued is trivial.
- Ajedi32 1y agoYou wouldn't necessarily know whether the certificates were obtained by the US government or another random attacker. They have the CA's name on them and the website name, not the attacker's name. I'm not saying there's no value in being able to detect when you're compromised. I'm just saying it would be better if the compromise wasn't possible to begin with.
- tialaramex 1y agoI'd be interested in technology to avoid being compromised if there was much evidence of compromise. When I looked at this ~10 years ago it was overwhelmingly "Fuck it they'll click past the warning" and today that doesn't work† but I don't work in an industry where it's my job to go find out what's happening to valuable targets (in that case military and government systems, typically in Asia or Africa) any more. † There are more obstacles, more awareness, and better tooling so "doesn't work" is over-stating it but I'd be very surprised if "fuck it" (ie just don't get certificates and impersonate an HTTP-only site instead) was enough today.
- throw_a_grenade 1y agoThey just MITMed on the link between the victim and it's immediate next hop, most likely by coercing the ISP (OVH). (See the writeup, where the admin discusses TTL values). No amount of multiview is sufficient if you control the uplink. Both DNS resolution and IP routing worked fine and IP packets were intercepted in attacker-controlled envirenment (on-path MITM box). What would somewhat help would be CAA record with specified ACME account key. The attackers would then have to alter DNS record, would be harder as you describe. (Or pull the key from VM disk image, which would cross another line).
- 1718627440 1y agoThey can also just tell some CA to sign a certificate.
- throw_a_grenade 1y agoI don't believe this happens. Should something like this happen, the CA would be immediately distrusted by browsers, not as punishment but to deter state actors. It would give CAs argument, “we won't do it, because it means end of business for us”. Compelling by the state to do something that destroys a company is illegal in many jurisdictions, in the law that prescribes what the state can order employees of the company and what they cannot.
- 20after4 1y agoHave you heard of https://en.wikipedia.org/wiki/United_States_Foreign_Intelligence_Surveillance_Court https://en.wikipedia.org/wiki/United_States_Foreign_Intellig...
- 1718627440 1y agoThe don't really need to order employees of the company, they can just do it. Either by completely owning a CA or by just going in and doing it. If it should be hidden, they can do it as part of an unrelated warrant. > the CA would be immediately distrusted by browsers, not as punishment but to deter state actors. Do you think browsers operate outside of states? > Compelling by the state to do something that destroys a company is illegal in many jurisdictions How would it destroy the company? It might affect reputation, but as long as it wasn't the company doing it on its own, they can just claim to be the victim (, which they are). It will only affect the company, if is becomes public knowledge, which the state actor doesn't want anyway. I don't think reputation to not respond to legal warrants is protected by the law. Also for example the USA is famous for installing malware on other countries head of state. Honestly this is the kind of law enforcement, which is fair in my opinion. It is much more preferable to mandated scanning (EU Chat Control), making the knowledge or selling of math illegal or sabotaging public encryption standards. No general security is undermined. It's just classic breaking in into some system and intercepting. Granted I think states shouldn't do it outside of their jurisdiction, but that is basically intelligence services fighting with each other.