Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
mdhardeman
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
31.
▲
by
mdhardeman
7y ago
Actually true root certs when evaluated by the browsers will have their name constrains within the root certificate themselves ignored. Modern browsers do respect name constraints of intermediate issuing certificates.
32.
▲
by
mdhardeman
7y ago
There's a broader reason. If the normal browsers break this, the response will just be that they do their own national fork of an open-source browser and distribute that to their people. The downside of pushing them to that is that th
33.
▲
by
mdhardeman
7y ago
They don't need to. In an authoritarian state, you just start blocking and breaking things. Everything you don't understand, you block. And then you make the user explain it to you and then if it's a use case you care about,
34.
▲
by
mdhardeman
7y ago
That's exactly what will happen if they all-out blacklist. The best near-term option may be a compromise: a special indicator in the browser UI that the connection has been set up in such a way that some organization may be monitoring
35.
▲
by
mdhardeman
7y ago
I think that's terribly optimistic. I think there are all kinds of people in the US government who would like to be able to point to a success story of a scheme like this, so that they'll have more ammunition in support of implem
36.
▲
by
mdhardeman
7y ago
In essence, what happens is they implement a "if we can't see it, you can't see it" policy.
37.
▲
by
mdhardeman
7y ago
I blame, in part, TLS 1.3, E-SNI, and DoH for this. Previously, a government could monitor what site a user is visiting just by looking at the TLS session startup. Even if it is hosted on a cloud provider and 100 different sites are hosted
38.
▲
by
mdhardeman
7y ago
The way that a real authoritarian government entity would handle that is... An agency is tasked with doing random sample captures of randomly selected target internet connections. Inventory all the types of traffic being exchanged. Flag any
39.
▲
by
mdhardeman
8y ago
The other respondents to this message more or less have it right. The way this stuff works is that when GEICO signed the deal to get access to this, they pinky-swore in a contract to only use the data certain ways. Often, the representative
40.
▲
by
mdhardeman
8y ago
No. But at a certain point, with the high speed modulations we have today, it is totally feasible to broadcast these passively to a multi-state region encompassing a radius of hundreds of miles. There's not a legitimate engineering re
41.
▲
by
mdhardeman
8y ago
What would be most effective would be a pair of rules in tandem: 1. Allow the location data to be utilized by the cellular carrier only for legitimate engineering purposes relevant to the delivery of the cellular services. (The network ne
42.
▲
by
mdhardeman
9y ago
True. Because almost all of the CAs utilize a web control mechanism, with many of them probably having processes not as rigorous as HTTP-01, it is likely that there would be significant backlash and a lengthier migration away from the metho
43.
▲
by
mdhardeman
9y ago
But if you're a web post with 10k+ users, what's the problem with the HTTP-01 challenge? You just allow .well-known/* to be passed on to reflect the challenge responses you've generated for the client, while 301 redirect
44.
▲
by
mdhardeman
9y ago
It is a rather limited protocol. Really, the implementation isn't so bad... In a perfect world. It's naive. It imagines there was a whole different set of operating circumstances at shared web hosts than the reality exhibits. I a
45.
▲
by
mdhardeman
9y ago
Agree 100%. I actually just joined the ACME mailing list to comment along those lines. I hope that wasn't against protocol. It will do favor to no-one to rush this. It's broken bad enough that it needs a fresh cycle of iteration
46.
▲
by
mdhardeman
9y ago
Let's Encrypt has also just added a new post in which they've been working tirelessly on a new nginx and apache plugin to certbot utilizing HTTP-01 validation: https://community.letsencrypt.org/t/help-test-cer
47.
▲
by
mdhardeman
9y ago
It is still an issue, actually. You misunderstand how the TLS balancer chooses which certificate to present. When the TLS connection comes in and presents a SNI name of "a.b.c.acme.invalid", the balancer checks its configuration t
48.
▲
by
mdhardeman
9y ago
No, that’s the problem. A lot of shared hosts will allow any customer to board a new website — as long as it’s not already taken on that hosting provider — then allow you to upload any TLS cert for that. So attacker requests to validate fo
49.
▲
by
mdhardeman
9y ago
Yes. Or even to the same name server, breaking out each whole label starting with _acme-challenge as its own independent zone, with its own access policies.
50.
▲
by
mdhardeman
9y ago
The DNS providers need to up their API game. The ISC BIND DNS server allows cryptographic authentication for updates with ACLs that let you get as granular as only being able to add/delete TXT records within this branch of zone X. In t
51.
▲
by
mdhardeman
9y ago
Ryan Sleevi of Google has discussed (specifically) such a possibility on the m.d.s.p group. Today's update from Let's Encrypt did allude under "ACME Protocol Updates" that there might be further work done to the protocol
52.
▲
by
mdhardeman
9y ago
I completely agree on the dns-01 challenge. Those who are migrating off of TLS-SNI-01 and have a capability to standardize on dns-01 will be better off in the long run. As you point out, domain control validation is best performed by havin
53.
▲
by
mdhardeman
9y ago
One would think that most of the Caddy users who previously used TLS-SNI-01 could also avail themselves of HTTP-01 validation.
54.
▲
by
mdhardeman
9y ago
It looks like Let's Encrypt has come up with the best plan possible for the goal of balancing mitigation of the security risks with compatibility for users. If their plan works out as they've laid out, and as certain recent commit
55.
▲
by
mdhardeman
9y ago
I agree with your position entirely, save for the "and if a shared provider has this issue, they might..." No one ever told the hosted service providers that they should explicitly guard for TLS SNI names unrelated to any name of
56.
▲
by
mdhardeman
9y ago
Indeed that the hosting providers do neither is a strong sign that both TLS-SNI-01 and TLS-SNI-02 and the mechanism I proposed would all be deficient to really address the issue of making this mechanism secure again.
57.
▲
by
mdhardeman
9y ago
An excellent example of a plausible attack scenario. Having said that, I think what we're all dying to know is what was it, initially, that made Carol so sad? And, indeed, was it that same sadness which stagnated, fermented, and evolve
58.
▲
by
mdhardeman
9y ago
The difficulty is the comparative security posture. The HTTP-01 and DNS-01 challenges really don't require the web hosts to get their $h1t together to improve security. (Technically, HTTP-01 could for some attack scenarios, but that w
59.
▲
by
mdhardeman
9y ago
Even if you could find them all and make automatic determinations as to whether or not they facilitate the vulnerability. (You really can't automate that as you need to be a customer of the host to really attempt to pull off the explo
60.
▲
by
mdhardeman
9y ago
It may make sense as a stopgap measure. Even then, you have a CA sticking out its neck on the assurances of a web host that isn't accountable to the root programs and isn't accountable to the CAB Forum. If that web host swears the
More ›