4 ms·
This seems to assume that the certificate chain in the software available within China is not compromised (aka, "obvious" way to detect MITM). I honestly don't
by markild 14y ago
This seems to assume that the certificate chain in the software available within China is not compromised (aka, "obvious" way to detect MITM).
I honestly don't know if this is a fair assumption or not, it just strikes me as weird that it is not mentioned when first mentioning the "great firewall"
- stock_toaster 14y agoI suppose they could be using cert pinning[1]. [1]: http://www.imperialviolet.org/2011/05/04/pinning.html http://www.imperialviolet.org/2011/05/04/pinning.html
- markild 14y agoAbsolutely. I wish they would address the topic, though. I interpret this article as if they mean that HTTPS solves all censoring and content sensing issues, regardless.
- StavrosK 14y agoYou mean Apple? In that case, I don't understand how that would help. The user never sees Apple's certificate, they only see the one presented by the MITM, no?
- markild 14y agoIn this case, if understand the concept correctly, it would be iTunes that pins the certificate authority for the iTunes server. One would still be vulnerable of a corrupt CA. The only solution to this would be to issue all certificates from an internal CA and verify this in your application.
- StavrosK 14y agoOr you could just harcode the certificate fingerprint and refuse to accept anything else. It's trivial when you own the client. I'm not sure if this would break when you needed to renew the certificate, but I guess you only update the signature, not the actual public key.
- phillmv 14y agoWhen you ship your own browser and OS you can prob get away with that.
- mtgx 14y agoBad news: apparently China does have compromised certificates: http://www.reddit.com/r/darknetplan/comments/156pyf/chinas_root_ca_and_the_security_implications/ http://www.reddit.com/r/darknetplan/comments/156pyf/chinas_r... I wonder if China will ever have a revolution, and if the "winners" will even want to revert to a "normal" Internet. The problem is most Chinese don't even know what that is.
- TazeTSchnitzel 14y ago>I wonder if China will ever have a revolution I think, personally, that the Chinese government will just get more democratic over time. It's worth noting that China is certainly moreso now than it was a few decades ago.
- CapitalistCartr 14y agoThe People's Republic of China is more liberal now than a few decades ago, but not more democratic. The leaders are still not elected by the people.
- MichaelGG 14y agoChina has a CA. But so do lots of small Latin American countries. It'd be silly to think that a government the size of China cannot compromise some little country's CA. It'd also be silly to think that they cannot get inside at least one US CA. Comodo has shown that their controls are lacking, and that wasn't even a directly compromised employee. So, China having a CA installed, while not great, certainly isn't giving them control they can't already get. Plus, why would they want to risk their own CA cert doing malicious things, where it'd be directly traceable to them?