|
|
Log in / Subscribe / Register

Ever-growing CRL?

Ever-growing CRL?

Posted Dec 6, 2024 12:16 UTC (Fri) by LtWorf (subscriber, #124958)
In reply to: Ever-growing CRL? by NYKevin
Parent article: Let's Encrypt sets date for ending OCSP support

In theory the old model was checking that you were who you say you are, while the new model only checks that you have control over the domain.

Of course, the "check" step was not done properly before.


to post comments

Ever-growing CRL?

Posted Dec 6, 2024 18:20 UTC (Fri) by tialaramex (subscriber, #21167) [Link] (3 responses)

The technology to have the CA warrant that "were who you say you are" still exists, and is exactly as functional as it was ten or twenty years ago. It's also exactly as useless.

The problems are manyfold, but most particularly the users do not know what they're supposed to be checking - in the US every single state (50 of them) gets to have their own business rules, and their own registrations, so you need to guess the "right" state for any particular business. For very local outfits it's probably the state where you are now, but for anywhere big enough to have an actual business structure they're likely registered somewhere financially & legally beneficial, such as Delaware. So who knows

Then, brands are what you care about as a customer, but the business name isn't the brand. Maybe you know them as "Big Kahuna Burger" but if their legal business name is "Edison Restaurant Group" too bad, the paperwork does not give the burger brand name and neither does the certificate.

Also, even assuming you do care that this site is owned by the "real" Edison Restaurant Group registered in Louisiana and not the one from Texas or California, the checking was always rather flimsy, it could hardly be otherwise. Somebody is going to get a business directory, they're about as reliable as a phone book was back when those existed. They're going to check that the person who asked for a cert can (say), read a Fax they sent to the right Fax number, something like that. How the check is performed is likely to be decided by the attacker, from a menu of options. Considering how relatively worthless this is, it's not exactly a huge security hole, but keep in mind that's what we're talking about - can you trick the person on some corporate front desk into letting you steal one fax, which you know when it's coming ? Or maybe make one phone call from a corporate number ? Or maybe make a decent reproduction of their corporate headed notepaper and wear a smart suit to a lawyer's office ? Weakest link applies, often it's "forge email from the right person" these days because modern business directories list email addresses.

Ever-growing CRL?

Posted Dec 7, 2024 3:22 UTC (Sat) by LtWorf (subscriber, #124958) [Link] (1 responses)

I was thinking more of europe where a .se domain (generally) means the website is swedish, and so on. Unless of course they are playing clever wordgames with the toplevel domain, like do.it or something like that.

Ever-growing CRL?

Posted Dec 9, 2024 21:27 UTC (Mon) by NYKevin (subscriber, #129325) [Link]

Physical locality is required by some ccTLDs, but it is far from universal, not always consistently enforced by the registries, and probably should not be relied on for security purposes. The same goes for geographic gTLDs,[1] at least in my estimation.

[1] : https://en.wikipedia.org/wiki/List_of_Internet_top-level_...

Ever-growing CRL?

Posted Dec 9, 2024 21:48 UTC (Mon) by NYKevin (subscriber, #129325) [Link]

IIRC there was also someone who created a business called "Identity Verified" and then got an EV certificate for it... which caused the words "Identity Verified" to appear next to (or in the case of mobile Safari, *in place of*) the URL bar. Now, if you're familiar with how certificates work, you can probably figure out that the blanket phrase "Identity Verified" is not a promise the browser can plausibly make, even if you don't know the details of what's supposed to be displayed there. But the average end user should not be expected to understand how the web's PKI works (or fails to work). From their perspective, if the browser is confidently displaying a green UI that says "Identity Verified," well, then it must be OK, right?

And this leads us to the broader problem with EV: You are allowing third parties to display (effectively) arbitrary text in the browser's trusted UI, in green and right next to a lock symbol, with the intent that users accept that text at face value. There are probably a thousand different kinds of mischief that attackers can make with that. The only reason they mostly didn't bother is because, back when EV was still a thing, you didn't even need HTTPS for phishing in the first place since so much of the web was still on plain HTTP.


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds