10 ms·
Nokia: Yes, we decrypt your HTTPS data, but don’t worry about it
- viveksec 14y agoI work in deep packet analytics and have interacted with several telcos and vendors. If you are developing a packet analytics or metrics product the temptation to tap into your production traffic, if only for validating your product is too strong. In our segment, access to live traffic is the primary "raw material" to develop, test, and enhance the products. So they may not use your data to "spy" but there is no protection against your data making it into packet captures (tcpdumps or pcaps) which then acquire a life of their own. I am not saying Nokia does this, but that any telco/vendor including this one who makes packet analysis products has to fight the temptation not to do it. I would never ever use a service that decrypts HTTPS traffic. How do we know that the other side is encrypted ? For all you know, the other side of the proxy could not even use SSL for services that offer both modes (google,facebook,twitter, etc etc).
- anuraj 14y agoThe Nokia Express browser and Opera Mini are built this way and technical folks know this. These browsers are used in resource constrained devices that cannot run a full fledged web browser and also conserve on bandwidth which is crucial for countries like India where 3G coverage is still patchy and expensive. I think user has the right to be better informed in this case. So is the case with Google Chrome which relays each and everything you do back to Google servers.
- justincormack 14y agoFunny there is an article today about how Safari had to run in 128MB RAM when it came out, which is apparently what these phones have. So writing a real browser may well still be possible.
- anuraj 14y agoA phone's 128MB memory is not same as PC's 128MB. Phones usually have execute in place (XIP) memories, which means the OS and apps share some space. Also each app is budgeted a certain memory (Phones use near real time OSs compared to usual OSs in PCs), so as not to exceed the memory limit anytime. There is no virtual memory to grow to. So the assumption is not correct especially for feature phones that do not use modern smart phone OSs which are more nearer (by no means same) to desktop counterparts.
- dagw 14y agoThe lower end Asha 30X series has 32MB of RAM and 10MB of internal storage to play with. Squeezing a real browser with acceptable performance into that is probably non-trivial. The second aspect is one of bandwidth. Pre-processed sites are a lot smaller than the full sites. Many people with these phones probably don't have data contracts with generous limits. And when you're paying pr byte and downloading over GPRS, every byte that doesn't have to be downloaded counts.
- rplnt 14y agoYour calculation forgot to include a decade of web evolution. Surely you agree that webpages from 2002 are different to those from 2012. Whether it's the size (images, javascript, html, css), complexity (css, html, javascript) or functionality (css, html, javascript).
- modeless 14y agoNow that this is known, how long until Nokia starts receiving government requests for HTTPS interception? I'm guessing less than a year. Of course, we'll never actually know.
- pdonis 14y agoI'm guessing it's already been happening for a while. The fact that the public just found out doesn't mean the government just found out.
- tobylane 14y agoThere's a difference between being the middle man so you can minify for the user, and logging all that goes through you. Just because we can't detect that change anyone who offers that service is a government lackey? I like Opera Mini, which is just like this. But I hope my bank blocks it.
- modeless 14y agoCertainly they don't log "all that goes through" them; that would be stupid and not really practical. However, nothing is stopping them from logging all data from specific persons of interest, or using MITM attacks to discover passwords, etc. Law enforcement, spy agencies, and others would be very interested in such a capability.
- yk 14y agoOf course there is a difference between just Mitm for compression and outright eavesdropping. But with this point of attack a government can simply walk to Nokia with a court order, and Nokia will comply, most likely without much of a fight. Or a little bit more abstract, the technical security is broken and the user relies on social norms for his privacy. The same social norms which forbid my ISP to sniff my non SSL traffic.
- darkarmani 14y ago> But with this point of attack a government can simply walk to Nokia with a court order, and Nokia will comply, most likely without much of a fight. Nokia might not even require a court order to let the government have access to your data. A court order is only to force Nokia to give access.
- benatkin 14y agoI'd love for Google to block all HTTPS traffic coming from Nokia's server, citing security concerns. That would make Nokia change their tune real quick.
- TallGuyShort 14y agoThat's great for security, but not for freedom. The problem is that people just assume they're secure, and they should be aware that if they're going to use these browsers, they're trusting Nokia with their information in exchange for a faster and more compact data transfer. But having Google refuse service because you choose to trust Nokia is silly. A warning shown to users would be a more palatable solution, in my opinion.
- gcb0 14y agoit's not insecure if you trust the company. should google block everypass.com just because it have your banking acount password? if i'm on a slow connection and have to use this browser to compress my connection to my bank, i will decide if i trust the browser to do so. I just think nokia should have been even more open about this. and probably gave me an option on the browser. In that they sinned.
- esrauch 14y agoI don't see how everypass.com is relevant. In this case when I go to https://www.google.com https://www.google.com I expect that any traffic can only be seen by Google, the entire reason I typed "https" was specifically so that it was only a conversation between me and the site that I'm connecting to and no other middle men. It is of no consequence what company it is; it would be inappropriate for Google to be seeing my encrypted traffic to hotmail and it would be inappropriate for Microsoft to see my encrypted traffic to gmail. Google continuing to serve traffic under those conditions is misleading and Google (or any other site that supports https) shouldn't allow it.
- nathan7 14y agoOf course, when Google breaks them they'll write a fully-fledged browser for those phones that works as smoothly as the thin-client one. Because they merely chose to do that not because the former is impossible, but because they wanted to be evil. They'll just "change their tune".
- zmmmmm 14y agoSurely this is a giant target painted on Nokia's proxy servers for any blackhat out there who wants to intercept a whole lot of https traffic? Seems like a horrible security incident just waiting to happen.
- elemeno 14y agoNo more so than any other proxy server.
- wlesieutre 14y agoCan a normal proxy server decrypt your HTTPS even it if wants to? I'm by no means an expect on cryptography, but I assume they're only able to do this because they can include their keys on Nokia devices and tell them to trust it. When I access a proxy on my computer, it can't do that. If an arbitrary proxy could MITM a secure connection, HTTPS would be useless.
- Mandatum 14y agoThe proxy server could theoretically do that. Whoever has access to your connection is able to.
- jarrett 14y agoNo, an ordinary proxy cannot do that. HTTPS is supposed to be end-to-end. I.e. the communications can only be decrypted by the two endpoints. One of the main reasons for signed SSL certificates is to prevent a middleman from masquerading as the endpoint and convincing your browser to negotiate encryption with the middleman rather than the real endpoint. So I presume the Nokia browser is complicit in this scheme.
- gcb0 14y agoIn the end, you have to trust the browser. google chrome sends all my pages to translation and what-not. I have to completely trust it. that's why i never use the compiled version but the chromium one only (hence not having access to any addon via the addon site, have to do some manual work there) Even besides the browser, how many computers don't I see the skype button next to phone numbers? would you trust skype is behaving and not sending your data to their servers? did you remember to disable this add-on for ssl pages?
- MichaelGG 14y agoThis will be true for any "server accelerated" browser that needs the server to render or modify content, like Opera Mini. How could they compress/optimize the pages coming to you, if they can't read it?
- Zirro 14y agoThey could exclude HTTPS-pages, or at least include an option to do so.
- anonymfus 14y agoIn case of Opera Mini client part of browser does not have technical ability to parse and render html.
- micampe 14y agoDoes it have the ability to access HTTPS content?
- rprasad 14y agoYes. If you read the terms of service for the Opera Mini browser, they disclose that HTTPS sessions are not end-to-end.
- kalleboo 14y agoIt also requires you to OK through a warning the first time you access an HTTPS site, so it's not a fact that's buried in some legalese.
- stordoff 14y agoYes, but Opera basically say that there are using a MITM approach: > To be able to do this translation, the Opera Mini server needs to have access to the unencrypted version of the webpage. Therefore no end-to-end encryption between the client and the remote web server is possible. If you need full end-to-end encryption, you should use a full web browser such as Opera Mobile. http://www.opera.com/mobile/help/faq/#security http://www.opera.com/mobile/help/faq/#security
- mixedbit 14y agoThey do it for caching purposes? What if some destination HTTPS servers return incorrect caching headers for sensitive data, because, hey, the content is encrypted so public caches have no way to store it. But now, Nokia caches can potentially store such sensitive content and leak it.
- Coincoin 14y agoIt's so they can compress the data and save on your data plan. You can't compress encrypted stuff, so they temporarily decrypt it, compress then reencrypt. They could have turned it off for HTTPS data though, but then all the mails would not get compressed and people would have said the browser doesn't work.
- obituary_latte 14y agoI understood it to be compression, not caching: >...and reiterated the point of the Xpress Browser’s compression capabilities... Seems like they are talking about what is going on on their network between the browser and the destination.
- idlecool 14y agoIs it even possible? HTTPS is used to avoid any possibility of man in the middle attack. How can nokia's proxy servers be able to decrypt that encrypted information unless they themselves have the private key?
- Coincoin 14y agoIt's not really a man-in-the-middle, as Nokia is actually controlling one of the two end points, that is, the browser.
- ollybee 14y agoThe only way I can think is if Nokia operate their own CA and configure the phones to trust it. They then issue their own certificate for any site you visit which your phone will trust. I don't think that's what is happening, we need further explanation. Although if that is what is happening it;s really bad as they would effectively be impersonating the sites.
- csours 14y agoMy guess is that the browser just won't tell you who the other party is. Whenever you go to a secure site you actually connect to (and are encrypted with) Nokia's server. That server then connects to the remote site securely.
- elemeno 14y agoIt's pretty standard for corporate proxy servers - at least in financial companies where theres regulations that tend to require some level of monitoring of external communications. It's a simple MITM attack, where the endpoint (your browser) has a whitelisted certificate for the proxy, so the browser is happy that it's talking to a correctly signed certificate that it trusts, and the proxy uses the the certificate for the other end of the connection.
- richardwhiuk 14y agoActually corporate proxy servers generally use CONNECT to allow HTTPS through.
- drcube 14y agoWhy is this necessary? Shouldn't all encrypted traffic be compressed to begin with? I'm ignorant of how SSL traffic is actually encrypted, but if you're already crunching the numbers to encrypt something, and a big part of encryption is eliminating redundancy, why isn't the data compressed at the same time? Seems like you could kill two birds at once and eliminate any reason to decrypt HTTPS data for caching purposes as well. It would cut down on traffic for the rest of us on the internet too. Or is this like CDN caching, where it's more about limiting latency than bandwidth?
- wikyd 14y agoI'm not sure about Nokia's service specifically, but in general these kinds of services do more than just zipping files. Some things they do: * resize images large images to match the screen resolution * limit the number of HTTP requests the phone itself is making
- tachim 14y agoThe point of most encryption algorithms isn't to compress the data or remove redundancy, at all. In fact, most widely used algorithms are block ciphers that don't change the size of the data.
- jsnell 14y agoIt's not just compression. These kinds of schemes can e.g. eliminate a massive number of extra roundtrips over a high latency mobile link. Or eliminate most uplink traffic completely (basically you'd just need to issue a request for the main page, all the subresources could automatically fetched by the proxy server and pushed to the client without it specifically requesting them). And that can be a huge win on mobile, since uplink tends to be way slower than downlink and often becomes a bottleneck for pages with many small resources.
- DanBC 14y agoThey like to crush images. I'm on a mobile dongle (T Mobile, UK) and I'll happily take some screenshots if anyone has some test gifs anywhere. Mine don't interfere with SSL. But a lot of other stuff is weird or broken.
- 14y ago
- welder 14y agoThe guy who originally discovered this: http://gaurangkp.wordpress.com/2012/12/05/nokia-proxy/ http://gaurangkp.wordpress.com/2012/12/05/nokia-proxy/ Does anyone have a reference to a law or regulation this would fall under? Does PCI compliance apply to this situation? If yes, then Nokia is not compliant to requirement 4.1: https://www.pcisecuritystandards.org/documents/Prioritized_Approach_V2.0.pdf https://www.pcisecuritystandards.org/documents/Prioritized_A...
- elemeno 14y agoWhy would Nokia care about PCI compliance? That's incumbent on the processor, not all the points inbetween.
- Coincoin 14y agoEven if they had to, they would be. Everything transmitted over a public network is encrypted. What assume they probably do is: Browser compress data -> Browser encrypt data for transmission to proxy -> Browser transmit encrypted data to proxy -> Proxy receive and decrypt the data -> Proxy decompress de data -> Proxy reencrypt the data for transmission to server -> Proxy transmit encrypted data -> Server receive and decrypt data I could be wrong but, at no point are the unencrypted data transmitted over a public network. The only places the data are not encrypted is on the client, the proxy and the server. You are already trusting Nokia party on the client side, they assumed you could also trust them on their proxy without asking you, which is moraly questionable, but surely not illegal. EDIT: Missing step above
- Firehed 14y agoMerely touching plaintext data at some point is enough to get scoped into PCI requirements, even if only in memory. Of course because they're not processing the payments, there's not a damn thing the networks can do to stop them; compliance can only be enforced when there's something to turn off (your merchant account) when you're not compliant. That's not the case here.
- aleprok 14y agoI will never again buy a Nokia phone.
- btilly 14y agoGiven the proliferation of Android and the iPhone, you probably wouldn't have anyways.
- aleprok 14y agoMaybe that might be so, but I still had Nokia until 2 weeks ago and still won't have either Android or iPhone. Thing is basically until now I have only used Nokia phones and that might be somewhat understandable when I say I'm Finnish.. Anyway security should never be exchanged for speed.
- hbharadwaj 14y agoYou do realize Nokia Lumia phones have IE as well as Xpress? This issue affects Xpress alone. You could use IE without any of this affecting you.
- dscrd 14y agoThe Lumias have this Xpress thing?! Why?
- hbharadwaj 14y agoEssentially, Nokia improves webpage load performances by utilizing data compression algos on their servers through Xpress - similar to Opera and Amazon Silk. In between, Nokia decrypts HTTPS traffic - Opera and Amazon apparently don't. So, effective use of Xpress could be limited to articles (The Verge), magazines and mailbox use could be done through IE or through the mail app. The problem is limited on the Lumia phones but it is a bigger deal just on their S40 phones.
- aleprok 14y agoThis is about trust and not about the one browser.
- Tichy 14y agoHow do they decrypt HTTPS? That shouldn't be possible? Are they exchanging certificates in the middle?
- mcherm 14y agoThey sold the phone, and so they controlled the browser installed on the phone. HTTPS is only secure if you can trust both ends: the receiving end and your browser. In this case, the browser was unreliable.
- jacquesm 14y agoNokia just killed their brand. And they can't even blame Android/Apple for it. Too bad for microsoft, they bet their mobile house more or less on Nokia and vice versa. Trust is a fragile thing.
- hosay123 14y agoHow is this any more insidious than already trusting the company to remotely update code on the device? Or (in the case of Google) on your desktop. As for the marginal gains you get from a direct SSL connection, at this stage it's been long demonstrated that the average Joe government can get their hands on CA certificates pretty easily. So the question really is how you expected to benefit from a direct SSL connection, given the already explicit trust you have in the company to provide secure software on your device with which to make the connection?
- jacquesm 14y agoWhen a device I own tells me I'm talking to my bank directly, but instead I'm talking to the producer of the device that's a man-in-the-middle-attack in progress. After that said producer of my device is definitely in my 'to be avoided' category.
- plasma 14y agoHow is this possible? Is there a built-in certificate on Nokia phones that accept the proxy server certificate (which must be a wildcard for everything)?
- marcosdumay 14y ago> Is there a built-in certificate on Nokia phones that accept the proxy server certificate (which must be a wildcard for everything)? Excatly.
- daftdoki 14y agoEven if Nokia isn't looking at your information, they're breaking the trust model of SSL even more than it already is. Since they would have to terminate SSL at their proxy server, you lose control of what certificate authorities you trust, and what certificates you trust. Not having one of these phones, I can't speak to the specifics, but it takes a lot of the ability for the user to verify the authenticity of the https connection.
- dakimov 14y agoIn a better world, this would be against the law.
- deleted 14y ago[deleted]
- antoncohen 14y agoThe Nokia Xpress Browser is not an HTTP web browser. It is a specialized client that talks to transcoding servers. It is designed for low-end phones in emerging markets. These phones have 128MB of RAM or less, they are not capable of running full web browsers. If a user has a phone capable of running a full browser (like the Lumia phones) and they choose to install the Nokia browser or Opera Mini to save on data usage, they are opting-in for the service. The compressing browser is not the default browser for Nokia phone running Windows Phone 7/8, MeeGo, Symbian^3, or S60. http://www.developer.nokia.com/Community/Wiki/User-Agent_headers_for_Nokia_devices http://www.developer.nokia.com/Community/Wiki/User-Agent_hea... There is no MITM attack. They are not spoofing DNS or forging SSL certs. They are providing a service that users are opting in to use. If you don't trust Nokia, don't use their phones. Even with end-to-end encryption, the data (including voice calls) is unencrypted on your phone until the software and hardware encrypts it. The maker of the software and hardware always has the capability to add eavesdropping code if they want.
- benatkin 14y agoWrong. It is an MITM issue. GMail and Twitter are free to offer non-SSL service but they choose not to. Also I'm very doubtful about the economics of offering a phone with a weak CPU and memory configuration. Aren't screens a big chunk of the price?
- magic_haze 14y agoI don't think the issue is quite as black-and-white: does the physical location where a computation is performed really of any importance in this case?, You don't have control over what's going on in the hardware anyway. I'm not condoning Nokia, but I really don't see any difference here.
- antoncohen 14y agoIf I use Thunderbird to send an email to foo@example.com, via Gmail, submitted with TLS encrypted SMTP on port 587, and Google decrypts my transmission and forwards it to mail.example.com unencrypted, is Google performing a MITM attack on my communication with example.com? No, they are providing the service I requested. The Nokia browser is essentially a thin client that communicates with a remotely hosted web browser. The remote web browser, running on Nokia's servers, does all the complicated JavaScript and advanced CSS stuff, and converts it to a dumbed down version that can be displayed on the phone. There clearly is a cost savings in using low-end parts. Not all screens are created equal, for example the Nokia Asha 306 uses a 240x400px resistive touchscreen. If you have ever used a phone with a resistive touchscreen you know how bad they are. It also has 32MB of RAM, 10MB of user storage, 2G data (not 3G), and no GPS. You can't run a WebKit + V8 browser on a phone with those specs, you just can't. The BOM for a Nokia Lumia 900 (high end, with a 480x800px capacitive touchscreen) is here: http://www.isuppli.com/Teardowns/News/Pages/Nokia-900-Carries-Bill-of-Materials-of-$209.aspx http://www.isuppli.com/Teardowns/News/Pages/Nokia-900-Carrie...
- Permit 14y agoWhy is it that Nokia gets ripped apart for this, but Opera-mini gets a free pass? This is not the default behavior for Internet Explorer, you'd have to opt-in.
- rplnt 14y agoIt's about page views. There's nothing revolutionary or wrong with this. It's specific browser for specific purpose. It's a documented behavior. It's been used for years. Nothing interesting about it.. unless you write and article like this to bait the readers and make them share it. Another option is the author is an incompetent idiot (news-writing-wise).
- logn 14y agoThis is a similar vulnerability to WAP. Nokia is providing a service: people with slow connections and cheap phones want it or need it. Sure, they should be more up front with users from the outset. But what I'd really like to see is Nokia working more closely with app developers to help them programatically detect these connections so users can be denied more easily in apps where security is critical. Some banks jumped through hoops trying to detect and shut down WAP connections.
- Udo 14y agoWhen Amazon did the exact same thing (offering a browser that had its endpoint on an external server) everybody was euphoric because it allowed a modern rendering engine to "run" on a very limited device. Now Nokia does the same thing for crippled phones and they're the bad guy.
- jargonjustin 14y agoNo, Amazon Silk routes HTTPS traffic directly to the origin server. https://www.eff.org/2011/october/amazon-fire%E2%80%99s-new-browser-puts-spotlight-privacy-trade-offs https://www.eff.org/2011/october/amazon-fire%E2%80%99s-new-b...
- hn-miw-i 14y agohttp://gaurangkp.wordpress.com http://gaurangkp.wordpress.com has this completely wrong. I wished he had published my comment on his blog (I was first post). Nokia is NOT intercepting https. The actual TLS session is run via a https proxy. No interception occurring. The guy who broke this has no understanding of the TLS protocol or PKI in general. He tried to say the root verisign certs in windows were being proof. bullshit. its 2 TLS sessions -- or TLS in TLS proxy. No problem. Go back to sleep.
- hn-miw-i 14y agoNokia is not intercepting your https! They are doing nothing dodgy here. Everyone who says "https interception" is hard, you are right. Unless you can install arbitrary trusted root He has presented no evidence of this. All he did was sniff the wire and saw a TLS session to Nokia. It's called an https proxy, genius. Ugh. This mAkes me so mad that people believe this crap.
- hn-miw-i 14y agoNokia pushed out an update that uses an http proxy for Phone to server TlS. The worst thing about this is that they have diluted their security model (tls in tls is resistant to single interception-- ie tor). They did this so boneheads that sniff the traffic will see the phone to server TLS rather than having it encrypted inside the phone to Nokia TLS. That's ignorant "researcher" you actually made it easier for the bad guys now.
- pyre 14y agoBad analogy time: It's like you're SSH'ing into a remote machine, then using w3m to access https://google.com https://google.com. Then you complain that your outgoing local connections are to the server instead of to google.com.
- rplnt 14y agoIt's actually a perfect analogy.
- dakimov 14y agoActually, I want to say: what the fuck?! Nokia are you that stupid? This is no joke. I used to think that when I use HTTPS my data are encrypted right in the browser, and I send some really sensitive data via HTTPS connections. "We're just compressing stuff... It's ok..." Really? I mean, really? Are you that lame? I don't use anything Nokia's anyway, but I hope other companies are not that stupid.
- dakimov 14y agoWhy is the comment greyed out only because some stupid jerks are not agree? What the hell? What if 99% of the clever people are agree? But clever people are still 5% of the human mass. This is a wrong ranking system, this is a dictatorship of the stupid. I am going to think of this as of the 'rejection therapy'. I am not going to conform the public's opinion anyway, just don't give a rat's ass.
- Tomek_ 14y agoThis is exactly the same thing Opera Mini is doing. Nothing shocking. The only (but crucial) difference is that Opera Mini is more transparent about it for the user (it explicitly warns the user when he's trying to access HTTPS sites), I bet Nokia will start do the same. Nothing to see here, move on.
- sparkinson 14y agoI understand that there is an expectation for Nokia to resolve this concern in some manner, but why do endpoint sites not simply block requests from the proxy? I mean if I was a bank it'd properly be in my interest to protect my customers from using a known insecure proxy (regardless of who manages it).
- slavak 14y agoWhat makes this proxy less secure than any other HTTPS proxy?
- cosmikduster 14y agoNow that we know Nokia is doing this, why shouldn't Banks, Facebook and Google reject any traffic coming from Nokia's proxy servers?
- alan_cx 14y agoPeople should stop thinking "geek". A mug punter is going to be freaked out that the advice that HTTPS means their data is secure will not care to understand technical BS that excuses the fact that HTTPS is not secure in this instance. "We" expect HTTPS to mean secure and unbroken along the way. This tells us that HTTPS might not mean secure at all. It doesn't matter what geekery is used to explain it, its not what it says on the tin.
- pyre 14y agoThe options are: 1. Trust Nokia (or Opera with Opera-mini) and use the product. 2. Have no browser on low-end phones. This is more a case of Nokia's product not explaining the security trade-offs to normal people. By choosing to use this browser, you are making the trade-off that it's impossible to have a secure (unbroken) connection between you and a website. Period. There's a secure connection between the site and Nokia, and another one between Nokia and you. Nokia (or anyone that hacks Nokia) can listen in the middle since it's not a end-to-end secure connection. | It doesn't matter what geekery is used to explain it Nothing is every truly, 100% secure. People like black-and-white answers. People either want "it's secure" or "it's not secure." People can't normally handle, "it's secure-enough for these use-cases, but not for these other use-cases." A normal browser could easily trust a fake-certificate that was issued incorrectly by a trusted source. I'm unsure how you fit these sorts of things into your world-view, but it would behove you to do so. | its not what it says on the tin. If you can find a tin that says so, you should attempt a false-advertisement claim.
- deleted 14y ago[deleted]