Skip to main content

Google discovers new security holes in SSL — is the entire system fundamentally flawed?

Data security

Share This Article

Google has discovered that an intermediate certificate authority had issued unauthorized certificates for multiple Google domains. The problem arose because the intermediate authority, MCS Holdings, had issued certificates for the Google domains, despite not holding those domains itself.
The reason it’s critical that companies not mint certificates for websites they don’t operate themselves is because doing so breaks the function of SSL itself. Here’s how the system is supposed to operate:
How SSL works
Your PC contacts a Google server, which returns a certificate. Your computer uses that certificate to encrypt a data session. The server confirms that the key is good and establishes the secure session with your PC. When certificates are signed by third parties, it allows the false server to execute a classic man-in-the-middle attack.
Main_the_middle
In a man-in-the-middle attack, an intervening certificate authority can pretend to be the genuine issuing authority, particularly if the intermediate certificate company is given the full authority of an issuing CA, which is what happened here. That’s not supposed to happen, as Google points out — the original Certificate Authority, CNNIC (the Chinese Internet Network Information Center) should never have given such authority to MCS Holding in the first place.

Fixing the TLS/SSL system

The problem with the SSL system — in addition to all the bugs, at least — is that it relies on the idea that Certificate Authorities will always issue good certificates. History has proven this simply isn’t true — multiple Certificate Authorities have been hacked, including companies like VeriSign and the now-defunct DigiNotar. Google wants to revamp the process of issuing certificates with its Certificate Transparency initiative. This project would:
  • Make it impossible (or at least very difficult) for a CA to issue a SSL certificate for a domain without the certificate being visible to the owner of that domain.
  • Provide an open auditing and monitoring system that lets any domain owner or CA determine whether certificates have been mistakenly or maliciously issued.
  • Protect users (as much as possible) from being duped by certificates that were mistakenly or maliciously issued.
Certificates would be logged, and the logs would be monitored by public servers that would periodically check to see if malicious or unauthorized certificates were being used across the net. For example, if Certificate Authority XYZ issued an unauthorized certificate for Gmail, a Certificate Transparency Monitor would detect the problem and alert Google itself. Finally, the logs and monitors would themselves be guarded by a cryptographic watchdog program, which would check to ensure that SSL certificates were properly logged and that the logs weren’t tampered with.
The other problem with the TLS/SSL system, beyond the fact that it relies on intrinsic trust, is that the system can be easily subverted. Unless certificates issued by a particular authority are revoked, those certificates can continue to be used to wreak havoc. This is why the recent Lenovo-Superfish debacle was so dangerous. Until Google, Microsoft, and Firefox updated their own software to reject the Komodo certificate, it remained available and functional — effectively end-running around any security that a website might try to provide.

Comments

Popular posts from this blog

Intel announces the first 14 nanometre processor

At the Computex conference in Taipei, chipmaker Intel has revealed a fanless mobile PC reference design using the first of its next-generation 14nm "Broadwell" processors. The 2 in 1 pictured here is a 12.5" screen that is just 7.2 mm thick with keyboard detached and weighs 670 grams.  The Surface Pro 3  – for comparison – is 9.1 mm thick and weighs 800 grams. It includes a media dock that provides additional cooling for a burst of performance. The next-generation chip is purpose-built for 2 in 1s and will hit the market later in  2014 . Called the Intel Core M, it will be the most energy-efficient Intel Core processor in the company's history with power usage cut by up to 45 percent, resulting in 60 percent less heat. The majority of designs based on this new chip are expected to be fanless, with up to  32 hours of battery life,  offering both a lightning-fast tablet and razor-thin laptop. Intel is also delivering innovation and performance for the ...

Use Cortana to define words for you in Windows 10

Microsoft’s Cortana has many uses including sending emails or checking the weather. One of the best uses though is a simple look-up feature for words and their definitions. Combined with the Hey Cortana voice recognition using Cortana to tell you quickly what a word means is a great hands-free tip. There are multiple ways to get Cortana to define a word. If you have Hey Cortana enabled you can simply blurt out your request: “Hey Cortana what is the meaning/definition of  inchoate ?” “Hey Cortana define  ubiquitously “ You can, of course, also just type in your request e.g “ define beatitude ” although this admittedly takes some of the speed (and fun) out of using the personal digital assistant. For many words, Cortana displays the definition within a card, and OxfordDictionaries or EncartaDictionaries powers it. Sometimes, if Cortana misunderstands you or does not have the definition, the assistant opens up a web page after performing a web search for...

IT Where Tech

IT Where Tech is a start-up technology provider from Pondicherry they provide Responsive web design ,Ecommerce design,Graphic Design CMS Websites,Logo Designs, Digital Marketing and Billing software

Facebook Now Supports PGP To Send You Encrypted Emails

You can now instruct Facebook to encrypt every email it sends to you so nobody — not even the NSA — is likely to be able to read your messages anytime soon. All you have to do is import your public PGP key into your Facebook settings and you’re good to go. The problem here, of course, is that most people have no idea how public/private key email encryption works and how to even get started with it. In the wake of Edward Snowden’s leaks, a number of organizations, including Google, promised to completely hide the complexities of end-to-end email encryption from regular users. Very few of these products have materialized so far, however — not for lack of trying, but because this is actually a very complex problem, both from a technical and user experience perspective. Facebook uses the well-established PGP scheme (the GNU Privacy Guard implementation of  OpenPGP, to be precise) to encrypt messages and tools lik...

Uber, Google and other tech employees form Coalition of Black Excellence

When black employee resource groups from a variety of tech companies come together, black magic happens. More specifically, black excellence happens. The Coalition of Black Excellence Week, spearheaded by Uber Litigation Counsel Angela Johnson in collaboration with black ERGs from over 40 tech companies like Facebook, Google, eBay, Lyft and Microsoft, kicks off this Monday in the San Francisco Yay (Bay) Area. The idea for CBE Week came in part from Johnson’s experiences living in Washington D.C., and being able to attend events put on by the Congressional Black Caucus, she told me at Uber’s headquarters this week. “When I moved out to the Bay Area, I really wished there were similar types of experiences for tech,” Johnson said. “And I thought if we could bring together different black ERGs, or diversity and inclusion committees, or people who were interested in some of the issues the black community is passionate about, a lot of positive change and impact could come from that....