4 ms·
Surely, this is an (admittedly broad and difficult) issue with CAs and the trust element of SSL authentication. By the theory of SSL, an 'attacker' is not suppo
by livnev 13y ago
Surely, this is an (admittedly broad and difficult) issue with CAs and the trust element of SSL authentication. By the theory of SSL, an 'attacker' is not supposed to have control over a 'trusted' CA, so SSL is 'supposed to' protect against this.
- lucb1e 13y agoI only thought of the Chinese govt issuing a certificate after writing half the post. Initially I was just going to comment on the easy possibility of MITM attacks. These would fail whenever anyone forced https into their address bar, but I think less than 5% of the people do that. That would mean just refusing connections for the <5% and still sniffing everyone else.
- paulgb 13y agoStrict transport security (http://en.m.wikipedia.org/wiki/HTTP_Strict_Transport_Security http://en.m.wikipedia.org/wiki/HTTP_Strict_Transport_Securit...) is an attempt to prevent exactly this. However assuming that the user is always on a MITM'd connection, a preloaded list in the browser becomes necessary.
- lucb1e 13y agoYes, doing this attack after a site is already publicly known is hard because of HSTS (if Github uses it), but slowly caches will expire and browsers will reset themselves, and the amount of http traffic will increase a lot.
- onedognight 13y ago> By the theory of SSL, an 'attacker' is not supposed to have control over a 'trusted' CA, so SSL is 'supposed to' protect against this. Every major government has a CA cert in your browser. SSL was obviously designed to be subverted in exactly this way. You won't even get a warning. Google pins their own certs in their own browser, but Moxy's Convergene.io or something like TACK would need to be implemented by Google and Mozilla for you to have a fighting chance.
- untothebreach 13y agoIs convergence.io still a viable project? Last time I checked the github repo it looked to be abandoned.
- livnev 13y agoExactly. But the important point is that the current situation with CAs may be flawed, but since ultimately the user has control over which certificates to trust, it will be possible to use better trust models (like convergence.io) to eliminate censorship. After that, we can indeed use encryption to fight censorship.