5 ms·
HTTPS over open wi-fi is trustworthy.
by coderzach 13y ago
HTTPS over open wi-fi is trustworthy.
- thirsteh 13y agoWell, only to the extent that the PKI model is trustworthy. If somebody can perform a MITM attack against you, you are wholly reliant on them not being able to generate a certificate for the domain you're looking at. It's better, but there are 650+ different companies who can sign certificates for all domains worldwide.
- tonfa 13y agoIf someone is able to do a MitM attack with a valid cert, I'd guess they have the capabilities of doing the attack upstream of the wifi. So having the wifi open or not won't matter much.
- thirsteh 13y agoI think that's an unreasonable assumption. It's far more likely that a CA is compromised than an ISP. Also, don't underestimate the power of e.g. sslstrip. Most users enter "google.com", not "https://google.com" https://google.com". If you're not careful, somebody will just remove all the SSL links on your pages, or lead you to another domain with a valid one, via DNS or HTTP redirects.
- bigiain 13y ago"It's far more likely that a CA is compromised than an ISP." I wonder if that's true? At a high enough stakes game - one would have to assume that state level actors have already trivially compromised both - the NSA clearly has pretty much 100% compliance from Verizon, and I don't think its going out on a limb to assume they've got similar compliance from at least one of (and possibly all of) the US based CAs. Egypt at a state level have been seen using fraudulent SSL certs - and you'd be foolish to assume there isn't equivalent CA access available to any government who has a root CA authority under their jurisdiction. But that's kind of a moot point - if the NSA is targeting me individually, I have to assume they'll gain access to pretty much everything - even if I strongly encrypt everything (and don't ever make a mistake doing so), many of the intended recipients of my communication are in jurisdictions where they've got enough power that wouldn't be able to resist the NSA's demands to reveal the unencrypted contents. (If they can ground head-of-states private planes in various European countries, there are probably very few places they cant "lean on" someone strongly enough to make it a not-very-difficult question about whether to give up my personal data.) "Lesser" state level actors - GCHQ, or ASIO here in .au for example - might not have quite such god-like global power, but I'm under no delusion about the privacy protection I've got against the "feeble compared to the NSA" local government intelligence organisation of whatever country I happen to be in, if it takes a personal interest in me. At the attack levels lower down though - carders, identity thieves, the generic "internet fraud" level attacker - I suspect ISPs are significantly more likely to be compromised than CAs - or at least the important part of the CA infrastructure that holds the root signing keys. I'd guess typical ISP infrastructure is not as well secured as typical CA root keys - and that zerodays, unpatched known vulnerabilities, and rogue/disgruntled/underpaid sysadmins in small (and perhaps even large) ISPs represent a much higher risk than non-state-level attacks via stolen CA keys.
- apendleton 13y agoBut if I want to attack you with an ISP compromise, I have to compromise your ISP, regardless of how well-secured it is. If I want to attack you with a CA compromise, on the other hand, I get the choose the absolute weakest-secured of the 600+ CAs there are.
- donutdan4114 13y agoMy thoughts exactly. DNS spoofing on open wi-fi is shockingly easy. Most people just "trust" certificates without looking at the details too. If I got a cert for facebook1234.com (just an example) and setup my server to grab credentials then send you to the real FB, nobody would notice. HTTPS is only good when you know what you're connecting to.
- gohrt 13y agoMaybe, but that requires the user reading this message in big red letters "This is probably not the site you are looking for!" and then clicking "Proceed anyway"
- mikeash 13y agoAnd clicking "proceed anyway" is exactly what a lot of users will do.
- vidarh 13y agoTrue.. Especially because users get conditioned to regularly. As an example: London Underground have partnered with a variety of commercial providers to offer free wifi at Underground and Overground stations. At least one of those providers forcibly redirects all traffic to plain http to show some "welcome" page, and won't let you use ssl at all. So users might get surprised once, see that the page they get finally get to is an official looking page, and then just shrug and continue. (which in this specific situation also creates the perfect setup for MITM'ing people without even have to go through the trouble of a cert: A portable base station, a higher powered antenna, a little setup to fake the same setup with a copy of their page, and voila you have a bunch of commuters happily tolerating surfing without SSL to get their free wifi while you intercept all their traffic)
- thirsteh 13y agoIt doesn't require that at all. You could simply strip the SSL and present a HTTP version of the page, and most people would be none the wiser. Or you could redirect to e.g. www.facebook23.com and have them log in there, with a nice little padlock. At no point would they get a certificate warning. They wouldn't get a certificate warning if you had compromised one of those 650+ CAs either, unless the site in question used certificate pinning (almost no sites do, currently.)
- tptacek 13y agoAndroid since 4.2 has supported certificate pinning --- though I don't know how it works with the Play Store.
- mike-cardwell 13y agoAssuming that the site you're using over HTTPS is: 1.) Not vulnerable to any CSRF flaws 2.) Uses Strict-Transport-Security 3.) Uses cookies with the "secure" flag set If any of those conditions are not met, then no, HTTPS over open wi-fi is not trustworthy.
- gohrt 13y agoCSRF has nothing much to due with wifi in particular, unless an HTTPS page is loading HTTP content, and a DNS hijacker is MITMing HTTP content.
- mike-cardwell 13y agoIf your site has a CSRF flaw, then a CSRF attack can be launched against it by a MITM as soon as you access any other HTTP site. So it's best to use a trusted network if the HTTPS site you're accessing has CSRF flaws. That was my point.