3 ms·
Chains of trust can't defend you from this. Only certificate pinning. IMO this shows why self signed is the way to go: There are no authorities you can trust.
by fosap 14y ago
Chains of trust can't defend you from this. Only certificate pinning. IMO this shows why self signed is the way to go: There are no authorities you can trust.
- tptacek 14y agoSelf signed is indistinguishable from "China is MITM'ing you". We agree about pinning. As pinning becomes more widespread, browsers that support it will become a sort of surveillance network for forged certificates. That's effectively what caused the Turktrust discovery.
- lucian1900 14y agoIt would be different if it worked like ssh, where key changes are warned about after the (optional) leap of faith.
- patio11 14y agoThe SSH model for SSL is a non-starter, because you can MITM bankofamerica.com or Gmail for an hour and find tens of thousands of people who just reinstalled Windows, bought a new iPad, etc etc, and they will fall instantly to your MITM attack. (And -- more's the hilarity -- if they try to go back to bankofamerica.com tomorrow it will look like the bank is trying to MITM them.)
- moonboots 14y agoThe new ssl pinning proposals work very similarly to ssh. When the user visits an https site with pinning enabled, the browser will remember the server's public key similar to ssh's known_hosts. You're correct that this won't protect against a MITM during this first visit and will cause confusion if an attacker pins his fraudulent public key. However, I would argue that pinning provides a large net security gain in practice. The same model of vulnerable initial visit but secure subsequent visits is used in HSTS to prevent ssl stripping attacks.