4 ms·
Browser vendors need to rethink the mostly blind eye they've been turning toward corporate DPI and silent MITM. I don't think browser vendors are necessarily r
by justcommenting 12y ago
Browser vendors need to rethink the mostly blind eye they've been turning toward corporate DPI and silent MITM.
I don't think browser vendors are necessarily responsible for Superfish or Privdog, but I do think they play a role when they make design choices that sacrifice more than most users realize at the altar of maximum compatibility without convenient alternative configuration options.
Even today, trust agility for CAs in Firefox is still one of the hardest-to-configure parts of the software for non-technical users. In a world of HSTS, why on earth should non-programmers have to click through a kludgy GUI for each of hundreds of CAs just to avoid trusting Chinese, Turkmenistani and various other CAs with no warnings by default? This seems like an area ripe for extension development; e.g. with something like RequestPolicy's categories defined by geography, level of paranoia, etc. - or AdBlock Edge's subscription lists. Firefox could pretty easily incorporate Certificate Patrol functionality and make it more usable for less technical users. And so on.
Companies producing this sort of malware deserve to be punished for misleading their customers and putting them at risk, but perhaps another solution is to pressure browser vendors to start thinking about the way crypto gets used with a lot more nuance as a potential attack surface, and from whose vantage point MITM confers transitive risk. When vendors leave those sorts of backdoors quietly open for corporate DPI, users often lose control over who else might try to use a similar type of backdoor.
There may be a legal difference between corporate DPI and Privdog, but we should stop pretending that there's a huge technical or ethical distinction between Privdog and browser vendors turning a blind eye to silent DPI against someone who does not get a say in it, and often does not even know about it.
Browser vendors hide behind 'compatibility' excuses for crappy defaults and glaringly absent warnings in much the same way PrivDog misleads people; browser vendors just tend to commit sins of omission rather than commission.
- PhantomGremlin 12y ago> Browser vendors need to rethink the mostly blind eye they've been turning toward corporate DPI and silent MITM. At this point I'm thinking it's more than a "blind eye", it's willful collusion. It's been too long since problem like these have been pointed out publicly. Moxie Marlinspike talked about SSL certificate problems back in 2011. Similarly, Certificate Patrol has tried to solve a real problem since 2012 if not earlier. But the browser vendors take very half-hearted steps to solve the problem. E.g. Firefox. Mozilla gets on the order of $300 million per year in revenue. Huh? WTF? Where does all the money go if high priority issues like this are attacked mostly by promises and baby steps? At what point do we begin to think that something that outwardly appears to be simple neglect is actually a lot more sinister? Before Edward Snowden's revelations I wasn't nearly as paranoid as the above sounds. Now, almost nothing I can think of is as bad as what the NSA and its ilk throughout the world have been doing to us for years.
- brazzledazzle 12y ago>Browser vendors need to rethink the mostly blind eye they've been turning toward corporate DPI and silent MITM. This kind of inspection is becoming more and more important for companies with every very public and expensive hack that occurs. Google, Microsoft and Apple all produce closed source software that they do not want leaked. They all have secrets and embarrassing private issues that have happened. I doubt you'll see cooperation from them in removing the ability to inspect traffic that leaves their networks or machines. >Firefox is still one of the hardest-to-configure parts of the software for non-technical users I'd agree that it's difficult for a non-technical user to configure, but that lack of easier configurability is a sign that Mozilla isn't really beholden to these organizations. If they were they'd just use the standard OS CA certificate stores like Safari, Chrome and Internet Explorer do. >There may be a legal difference between corporate DPI and Privdog, but we should stop pretending that there's a huge technical or ethical distinction between Privdog and browser vendors turning a blind eye to silent DPI against someone who does not get a say in it, and often does not even know about it. I agree, but I also recognize the importance of this feature to companies, big or small. While Chrome and Internet Explorer both have consumer and enterprise versions/configurations for their browsers, they could split security features with the user in mind too. I'd say Safari could do more in general but I feel like Apple has such a love/hate relationship with enterprise customers that it would be hit or miss in execution.
- jgraham 12y ago> Browser vendors need to rethink the mostly blind eye they've been turning toward corporate DPI and silent MITM. It is unclear to me if browser vendors could actually do anything meaningful here. After all a sufficiently motivated company could just deploy a private fork of an open source browser with any code changes they want. No doubt, if there is demand, someone would be happy to sell pre-customised versions of these browsers. The only restriction they would have is that they couldn't call the result "Firefox" or "Chrom[ium]", but since they set the IT policy, requiring all employees to use FooCorp Internet Browser isn't a problem. I guess the trademark issue, but really only the trademark issue, does make that approach less viable for adding MITM "capabilities" to OEM-distributed browsers. (note: I work for Mozilla, but am not a security expert)
- justcommenting 12y agoI actually think reframing these issues as something that might necessitate a fork for corporates could be good for all involved because that hopefully would mean less egg on Mozilla's face when someone finds out they're being DPIed. There's a lot more nuance than I've acknowledged, but I'd much rather people make a fairly consistent set of assumptions about the trustworthiness of Firefox and a second, different set of assumptions about corporate MITMfox. Even though I'm not a fan of it, I also recognize that companies own their assets and need to protect their networks. But should Firefox stay completely quiet by default when an IT department MITMs an employee's traffic? Even if we all acknowledge the same IT department could turn those warnings off, I think it would still be a start. This will always be a cat-and-mouse game and I agree that Mozilla may not be able to permanently 'win' on behalf of users, but I think browser vendors in general could do more to shift norms and change the 'framing' of whether users see (for example) a monkey-in-the-middle icon instead of a lock icon by default when they're being MITMed by adware or corporate DPI.