4 ms·
https://www.imperialviolet.org/2011/05/04/pinning.html https://www.imperialviolet.org/2011/05/04/pinning.html https://www.net-security.org/secworld.php?id=1236
by eliasmacpherson 13y ago
https://www.imperialviolet.org/2011/05/04/pinning.html https://www.imperialviolet.org/2011/05/04/pinning.html
https://www.net-security.org/secworld.php?id=12369 https://www.net-security.org/secworld.php?id=12369
https://news.ycombinator.com/item?id=5141342 https://news.ycombinator.com/item?id=5141342
I'm pretty sure it happens, trustwave apparently issued a cert for these purposes and it's claimed other CA's have done the same. It's a hassle to do, but the goal is to detect and prevent corporate espionage. Most corporates have their own OS media - installing from outside sources without adding corporate security required software is forbidden.
I assume this is how the certs get on to the machines. A browser plugin would be more transparent, possibly defeating the purpose.
- jakejake 13y agoI remember reading about that trustwave incident, that is definitely messed up! I was just really trying to say that adding a rogue CA to the browser trust list vs installing a plugin both require admin permission and are both "noticeable." So neither of them are really ideal for serious espionage. In which case they're only good for non-secret employee monitoring. So, in that case, might as well go with a plugin because it would be the simpler solution. If you're talking about a compromised "root" CA like trustwave or something where a stock browser will trust fake certs - now you're talking about a technique suitable for espionage or black hat activities.
- eliasmacpherson 13y agoA browser plugin is really really obvious, whereas if you take a look at the CA's in firefox - there's hundreds. All you need is one subtly different from what's expected - barely noticeable. https://www.bluecoat.com/products/proxysg https://www.bluecoat.com/products/proxysg I think you'll find the above product interesting. Apparently anti-virus vendors have similar programs - to prevent malware being downloaded over https behind a corporate proxy. It seems that CDN's such as cloudflare and akamai take the websites SSL _private_ keys too. http://blog.cloudflare.com/introducing-strict-ssl-protecting-against-a-man-in-the-middle-attack-on-origin-traffic http://blog.cloudflare.com/introducing-strict-ssl-protecting... This blog post is a fancy way of saying that cloudflare content serving customers now have the option of encrypting the link between cloudflare and them. Note that users can still be MITM'd at the cloudflare site - even with the new arragement.