4 ms·
The HSTS commits /maybe/ suggest that Google thinks a Verisign intermediate was signing MITMs for Google properties. They just blacklisted "VeriSignClass3SSPInt
by semenko 13y ago
The HSTS commits /maybe/ suggest that Google thinks a Verisign intermediate was signing MITMs for Google properties. They just blacklisted "VeriSignClass3SSPIntermediateCA"
See: https://chromiumcodereview.appspot.com/23523051 https://chromiumcodereview.appspot.com/23523051
Note that the associated bug is private (https://code.google.com/p/chromium/issues/detail?id=173460 https://code.google.com/p/chromium/issues/detail?id=173460).
There's a good explanation of the "bad_static_spki_hashes" parameter here: http://ritter.vg/blog-cas_and_pinning.html http://ritter.vg/blog-cas_and_pinning.html
- andrewcooke 13y agoif that's the case, how did they get the private key from verisign? was it stolen? did verisign simply give them it? or was it obtained under some kind of legal process? if it was under a legal process, doesn't this raise additional questions about the judicial overview - did they realise how broad this was?
- anon1385 13y agoSounds like it could be any of those things: they use all those tactics. http://www.nytimes.com/2013/09/06/us/nsa-foils-much-internet-encryption.html?pagewanted=all http://www.nytimes.com/2013/09/06/us/nsa-foils-much-internet... Because strong encryption can be so effective, classified N.S.A. documents make clear, the agency’s success depends on working with Internet companies — by getting their voluntary collaboration, forcing their cooperation with court orders or surreptitiously stealing their encryption keys or altering their software or hardware. N.S.A. documents show that the agency maintains an internal database of encryption keys for specific commercial products, called a Key Provisioning Service, which can automatically decode many messages. If the necessary key is not in the collection, a request goes to the separate Key Recovery Service, which tries to obtain it. How keys are acquired is shrouded in secrecy, but independent cryptographers say many are probably collected by hacking into companies’ computer servers, where they are stored. To keep such methods secret, the N.S.A. shares decrypted messages with other agencies only if the keys could have been acquired through legal means. “Approval to release to non-Sigint agencies,” a GCHQ document says, “will depend on there being a proven non-Sigint method of acquiring keys.” Sounds like there are plenty of possibilities: they have agents working at verisign/they broke into verisign (either physically or electronically)/they just asked and verisign said ok/they used legal processes.
- juhanima 13y ago> they used legal process They used a secret legal process. There, fixed that one for you!
- vabmit 13y agoDidn't Assange say in a (secretly?) recorded video where he was talking with Schmidt and another person that while the Americans got trusted root keys from Diginotar, the Chinese hacked Verisign and grabbed their root keys? I'll see if I can find the video.
- socillion 13y agoGreat tip! It's not exactly what you laid out, but here's the interview you're probably thinking of (ctrl+f verisign): http://wikileaks.org/Transcript-Meeting-Assange-Schmidt http://wikileaks.org/Transcript-Meeting-Assange-Schmidt Quoting Julian Assange: I have been told actually that VeriSign... has actually given keys to the US government. Not all, but a particular key. Very interesting.
- pflanze 13y agoI don't get why everybody talks about Verisign or others giving them "keys". The NSA just need certificates for their own key, right? The only private key that Verisign could give them would be their signing key, which seems much too powerful and central for a signing authority to hand out.
- peter487 13y agoRaw decode of the cert that has been blacklisted. http://pastebin.com/4wJXTsR4 http://pastebin.com/4wJXTsR4 Let the speculation begins.
- deleted 13y ago[deleted]
- herf 13y agoThe checkin says "Win32/Sirefef.gen!C" uses it somehow. A virus that acts as a CA?