Web Images Videos Maps News Shopping Gmail more »
Recently Visited Groups | Help | Sign in
Google Groups Home
Trusted CA issuing SSL server certs with unvetted FQDNs!
There are currently too many topics in this group that display first. To make this topic appear first, remove this option from another topic.
There was an error processing your request. Please try again.
flag
  9 messages - Collapse all  -  Translate all to Translated (View all originals)
The group you are posting to is a Usenet group. Messages posted to this group will make your email address visible to anyone on the Internet.
Your reply message has not been sent.
Your post was successful
 
From:
To:
Cc:
Followup To:
Add Cc | Add Followup-to | Edit Subject
Subject:
Validation:
For verification purposes please type the characters you see in the picture below or the numbers you hear by clicking the accessibility icon. Listen and type the numbers you hear
 
Nelson Bolyard  
View profile  
 More options Aug 19 2008, 8:40 pm
Newsgroups: mozilla.dev.tech.crypto
From: Nelson Bolyard <NOnelsonS...@NObolyardSPAM.com>
Date: Tue, 19 Aug 2008 17:40:23 -0700
Local: Tues, Aug 19 2008 8:40 pm
Subject: Trusted CA issuing SSL server certs with unvetted FQDNs!
In a Network World column,
   http://www.networkworld.com/community/node/31124

the author writes:
> At Black Hat ‘08 there was a great demonstration of how valid “internal
> testing only” FQDN certificates for URLs that you don’t control can be
> obtained by anyone asking. The one obtained by the researcher at Black Hat
> was for MSFT’s https://login.live.com site, he didn’t disclose the CA that
> issued it to him but it was one that was trusted in IE by default.

This is, of course, very serious, as it casts doubts on the value of SSL
and PKI for all products that use SSL.

If we can determine what CA is doing this, I propose we pull them from
the trusted CA list immediately.


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Wan-Teh Chang  
View profile  
 More options Aug 19 2008, 9:02 pm
Newsgroups: mozilla.dev.tech.crypto
From: "Wan-Teh Chang" <w...@google.com>
Date: Tue, 19 Aug 2008 18:02:27 -0700
Local: Tues, Aug 19 2008 9:02 pm
Subject: Re: Trusted CA issuing SSL server certs with unvetted FQDNs!
On Tue, Aug 19, 2008 at 5:40 PM, Nelson Bolyard

<NOnelsonS...@nobolyardspam.com> wrote:
> In a Network World column,
>   http://www.networkworld.com/community/node/31124
> the author writes:

>> At Black Hat '08 there was a great demonstration of how valid "internal
>> testing only" FQDN certificates for URLs that you don't control can be
>> obtained by anyone asking.

This means that CA doesn't even do "domain validation", right?

Wan-Teh


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Eddy Nigg  
View profile  
 More options Aug 19 2008, 9:15 pm
Newsgroups: mozilla.dev.tech.crypto
From: Eddy Nigg <eddy_n...@startcom.org>
Date: Wed, 20 Aug 2008 04:15:46 +0300
Local: Tues, Aug 19 2008 9:15 pm
Subject: Re: Trusted CA issuing SSL server certs with unvetted FQDNs!
Nelson Bolyard:

> This is, of course, very serious, as it casts doubts on the value of SSL
> and PKI for all products that use SSL.

> If we can determine what CA is doing this, I propose we pull them from
> the trusted CA list immediately.

Ask them!

--
Regards

Signer: Eddy Nigg, StartCom Ltd.
Jabber: start...@startcom.org
Blog:   https://blog.startcom.org


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Nelson Bolyard  
View profile  
 More options Aug 19 2008, 10:20 pm
Newsgroups: mozilla.dev.tech.crypto
From: Nelson Bolyard <NOnelsonS...@NObolyardSPAM.com>
Date: Tue, 19 Aug 2008 19:20:29 -0700
Local: Tues, Aug 19 2008 10:20 pm
Subject: Re: Trusted CA issuing SSL server certs with unvetted FQDNs!

Wan-Teh Chang wrote:
> On Tue, Aug 19, 2008 at 5:40 PM, Nelson Bolyard
> <NOnelsonS...@nobolyardspam.com> wrote:
>> In a Network World column,
>>   http://www.networkworld.com/community/node/31124
>> the author writes:

>>> At Black Hat '08 there was a great demonstration of how valid "internal
>>> testing only" FQDN certificates for URLs that you don't control can be
>>> obtained by anyone asking.

> This means that CA doesn't even do "domain validation", right?

I believe so.  I seriously doubt that the presenter of this demo
(whoever it was) really controlled the domain for live.com.

On the other hand, it is possible that the domain validation was performed
but that it was deceived through the use of DNS attacks.  In his slides
on the subject of DNS attacks, Dan Kaminsky did say that it was possible
to deceive domain validation through DNS attacks.

See http://www.doxpara.com/DMK_BO2K8.ppt slides 76-79, especially slide 77

Eddy Nigg wrote:
> Ask them!

Who?

I have no information about this beyond what I already posted in this thread.


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Thorsten Becker  
View profile  
 More options Aug 20 2008, 4:38 pm
Newsgroups: mozilla.dev.tech.crypto
From: Thorsten Becker <tb-news-2...@arcor.de>
Date: Wed, 20 Aug 2008 22:38:15 +0200
Local: Wed, Aug 20 2008 4:38 pm
Subject: Re: Trusted CA issuing SSL server certs with unvetted FQDNs!

Nelson Bolyard wrote:
> On the other hand, it is possible that the domain validation was performed
> but that it was deceived through the use of DNS attacks.  In his slides
> on the subject of DNS attacks, Dan Kaminsky did say that it was possible
> to deceive domain validation through DNS attacks.

I think domain validation could be deceived using DNS attacks, but in this
case this was apparently not necessary:

http://www.networkworld.com/community/node/30822

"Michael started his talk by detailing how he was able to purchase a
certificate from a major CA with a FQDN of an existing fortune 500
company’s website! How you ask is this possible, well when filling out the
request form he simply checked the box that stated that the certificate was
not going to be used on the internet and was for internal testing only."


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Nelson B Bolyard  
View profile  
 More options Aug 20 2008, 5:58 pm
Newsgroups: mozilla.dev.tech.crypto
From: Nelson B Bolyard <nel...@bolyard.com>
Date: Wed, 20 Aug 2008 14:58:06 -0700
Local: Wed, Aug 20 2008 5:58 pm
Subject: Re: Trusted CA issuing SSL server certs with unvetted FQDNs!

I'll be convinced when I see the cert and/or see the web site's enrollment
page with that feature.  There's one CA that can kiss it's place in the root
list good-bye.

    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Eddy Nigg  
View profile  
 More options Aug 20 2008, 7:39 pm
Newsgroups: mozilla.dev.tech.crypto
From: Eddy Nigg <eddy_n...@startcom.org>
Date: Thu, 21 Aug 2008 02:39:54 +0300
Local: Wed, Aug 20 2008 7:39 pm
Subject: Re: Trusted CA issuing SSL server certs with unvetted FQDNs!
Nelson B Bolyard:

> I'll be convinced when I see the cert and/or see the web site's enrollment
> page with that feature.  There's one CA that can kiss it's place in the root
> list good-bye.

Quoting from the article:

"The one obtained by the researcher at Black Hat was for MSFT’s
https://login.live.com site, he didn't disclose the CA that issued it to
him but it was one that was trusted in IE by default."

First of all, this CA doesn't have to be in NSS, but is in IE. Luckily
not every CA which is trusted by MSIE is also in Mozilla. Some of you
might be surprised about which aren't in NSS and most likely rightly so.
MS doesn't have the same requirements as Mozilla. Not sure now if they
require domain validation, but maybe not...

Second, Mozilla and/or Microsoft might be able to force the disclosure
of that CA. Most likely they removed the evidence at the web site and
revoked the certificate by now, but the certificate itself might be
prove enough.

--
Regards

Signer: Eddy Nigg, StartCom Ltd.
Jabber: start...@startcom.org
Blog:   https://blog.startcom.org


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Kyle Hamilton  
View profile  
 More options Aug 20 2008, 7:43 pm
Newsgroups: mozilla.dev.tech.crypto
From: "Kyle Hamilton" <aerow...@gmail.com>
Date: Wed, 20 Aug 2008 16:43:19 -0700
Local: Wed, Aug 20 2008 7:43 pm
Subject: Re: Trusted CA issuing SSL server certs with unvetted FQDNs!
2008/8/20 Robert Relyea <rrel...@redhat.com>:

> Luckily, Michael also stated that most CA's rejected his requests. But it
> only takes one CA to spoil the party.

It only takes one CA to spoil the party, because there's no
presentation to the user of who's responsible for the muckup.

Of course, if he doesn't provide the certificate and proof that he has
the private key to it, I'm going to believe this as an unfounded
attack against the credibility of the PKI system in general.

It's called "put up or shut up".  Unfortunately, since there's no
single "owner" of the PKI, there's no place/person who can directly
claim slander or libel and thus damages, which essentially makes these
types of attacks damaging without recourse.

-Kyle H


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Nelson B Bolyard  
View profile  
 More options Aug 20 2008, 7:55 pm
Newsgroups: mozilla.dev.tech.crypto
From: Nelson B Bolyard <nel...@bolyard.com>
Date: Wed, 20 Aug 2008 16:55:27 -0700
Local: Wed, Aug 20 2008 7:55 pm
Subject: Re: Trusted CA issuing SSL server certs with unvetted FQDNs!

Kyle Hamilton wrote:
> 2008/8/20 Robert Relyea <rrel...@redhat.com>:
>> Luckily, Michael also stated that most CA's rejected his requests. But it
>> only takes one CA to spoil the party.
> Of course, if he doesn't provide the certificate and proof that he has
> the private key to it, I'm going to believe this as an unfounded
> attack against the credibility of the PKI system in general.

> It's called "put up or shut up".  Unfortunately, since there's no
> single "owner" of the PKI, there's no place/person who can directly
> claim slander or libel and thus damages, which essentially makes these
> types of attacks damaging without recourse.

I agree with you completely on the above quoted points.

Someone from Mozilla is trying to get info about the CA from the presenter.


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
End of messages
« Back to Discussions « Newer topic     Older topic »

Create a group - Google Groups - Google Home - Terms of Service - Privacy Policy
©2009 Google