4 ms·
Im at a loss, but my first instinct is to say that server certs arent validated properly AT ALL, so I fail to see how client certs would do any better. For all
by tomgirl1 13y ago
Im at a loss, but my first instinct is to say that server certs arent validated properly AT ALL, so I fail to see how client certs would do any better.
For all the hype over PFS (perfect forward secrecy) I dont see how how MITM attacks are stopped because cert validation is so bad or nonexistent I dont see applying more certs (plus diffie hellman) to be a solution.
- mtrimpe 13y agoThey're as secure as your ability to keep the private keys private, just like with server certs. As far as MITM and PFS goes; that's handled just the same as regular SSL. Using a client cert doesn't affect that at all.
- tomgirl1 13y agoWhich is not secure at all. you can MITM a typical SSL connection in so many ways SSL might as well not exist. No real cert validation, forged certs, proxy replays. SSL is a joke.
- icebraining 13y agoProxy replays? How so? As for cert validation / forged certs, they're only problematic because we want to authenticate a server we have never talked to before. With clients certs, the same doesn't apply: the server just needs to ensure the client is the same as the one who registered the account, so there's no need for the whole CA enchilada.
- xnyhps 13y agoMost places where you can authenticate with SSL client certs allow you to add your own self-signed certificate and authenticate using that. All the validation you need is to check wether the cert is in the user's list. You can only forge that by stealing the private key. There's really no reason to only allow CA signed client certs.
- booyahdog 13y agoThats not the question. The question is how is a cert validated properly? For example, you can have a parent CA certificate and iOS (just as one example) will accept the child cert no questions asked. Also if you forego CA and self sign, how do you verify your OWN cert? How? A proxy can just pass it through to your client if you use server trust. So you have a problem, the OS cant validate your cert and you have limited means to validate your own cert. All you know is you encrypted something. Any joe can buy a CA cert and fool iOS (just as an example) but not only that, the govt can easily forge CA keys and forge certs. So then what do you do? Your server cert can easily be forged or replayed through a proxy.
- booyahdog 13y agoI dont mean to be rude, or create doubt, but you must realize that SSL is completely insecure.
- peterwwillis 13y agoYou can't MITM an SSL session with validly CA-signed certs unless you've pwnd the CA, web server or end user's machine. And I don't know what you're going on about with regarding "no real cert validation". If it's valid, it will be validated. There's nothing wrong with it when it's done right.
- superuser2 13y agoThe point isn't eavesdropping prevention, it's authentication that's not broken (like passwords).