4 ms·
The difficulty of making sure your website is broken
- paulirish 6mo agohttps://badssl.com/ https://badssl.com/ also offers several test subdomains in the same vein.
- NicolaiS 6mo agobadssl.com is an amazing tool especially for testing "TLS intercepting" boxes. I've seen more than one fortune 500 company that re-sign certain broken certs with their own CA, allowing silent MITM.
- dropboot 6mo ago[dead]
- bheadmaster 6mo agoIncomplete chain seems to load on Android Chrome...
- bullen 6mo agoMeanwhile HTTP keeps working just fine and is decentralized. Just "add your own crypto" on top, which is the ONLY thing a sane person would do. 3... 2... 1... banned?
- xandrius 6mo agoDid you self-ban?
- bullen 6mo agoXD Nope, more like self destruct! ;)
- horsawlarway 6mo agoto actually tackle this (on the off chance you're serious, I'm assuming not) - this doesn't work. The payload that implements your crypto cannot be delivered over http, because any intermediate party can just modify your implementation and trivially compromise it. If you don't trust TLS, you have to pre-share something. In the case of TLS and modern browser security, the "pre-shared" part is the crypto implementation running in the browser, and the default trusted store of root CAs (which lives in the browser or OS, depending). If you want to avoid trusting that, you've got to distribute your algorithm through an alternative channel you do trust.
- bullen 6mo agoYou are right presharing is a requirement, unless you hash the keys used to encrypt the secret into the secret itself, but that can only be prooven later on a channel where the same MITM is not present. Work in progress, that said presharing solve(d/s) enough for the world to dump DNS and HTTPS in a bin and light it on fire now, because nobody has the power to implement all the MITM needed if everyone "makes their own crypto" on top of allready shared secrets! Circular arguments, wishful thinking and all...
- NooneAtAll3 6mo ago> default trusted store of root CAs (which lives in the browser or OS, depending). speaking of that, is there any way to verify that stored certificates are actually valid?
- deleted 6mo ago[deleted]
- ipython 6mo agoInteresting. Chrome (146, macOS) shows no error messages on the revoked cert pages, but Firefox does (also macOS).
- mcpherrinm 6mo agoYeah, Chrome only partly supports revocation (Not sure exactly the criteria, but our test sites don't match it).
- moralestapia 6mo agoSame with Brave, so it is a Chromium thing.
- omoikane 6mo agoChrome doesn't want to perform online revocation checks according to this page: https://chromium.googlesource.com/chromium/src/+/HEAD/docs/security/faq.md#what_s-the-story-with-certificate-revocation https://chromium.googlesource.com/chromium/src/+/HEAD/docs/s... found via: https://issues.chromium.org/issues/471199592#comment3 https://issues.chromium.org/issues/471199592#comment3
- lifis 6mo agoVanadium, Chrome and Firefox (all for Android) all accept all the revoked certificates... But revoked.badssl.com is considered revoked
- RunningDroid 6mo ago> Vanadium, Chrome and Firefox (all for Android) all accept all the revoked certificates... But revoked.badssl.com is considered revoked Firefox Beta (150.0b7) is accepting all of the revoked certs on my device
- sureglymop 6mo agoI don't think those certs are revoked yet.
- nottorp 6mo agoIn the same direction, I once wanted to test an embedded device on crap wifi. So I just ordered the cheapest AP I could find. Except the damn device worked perfectly. Slow but rock solid. One of our testers at $CURRENT_JOB also has trouble simulating a crap network, because our network is good.
- Groxx 6mo agoSome proxies, iptables extensions, and OS-provided tools exist - there's almost certainly a combo that would work for them. What platform? Unless it's for a custom physical device, then uh. idk. Probably something, proxying through another computer that is hosting a separate wifi network? But likely a lot harder.
- nottorp 6mo agoI think he figured it out eventually, used some software tool. But I heard the complaining first.
- deleted 6mo ago[deleted]
- gnopgnip 6mo agoYou can simulate bad wifi with the throttling option on the network tab of your browser's developer tools
- dieulot 6mo agoThat’s an unreliable way of simulating an unreliable network, as overviewed in https://calendar.perfplanet.com/2016/testing-with-realistic-networking-conditions/#browser_level_traffic_shaping https://calendar.perfplanet.com/2016/testing-with-realistic-...
- patmorgan23 6mo agoSlow networks != Bad networks. Bad networks could be slow, or drop random packets, or corrupt packets, or have jitter, etc
- JackSlateur 6mo agoNotice how your browser happily accepts the expired certificates :)