|
|
Log in / Subscribe / Register

Security quotes of the week

In shutting out governments from looking over our collective shoulders have we instead run straight into the embrace of an even worse and far more insidious model of digital stalking in the guise of surveillance capitalism? Do the application providers such as Meta or Google have access to data about us that we ourselves were never privy to in the first place?

In the shift to shut out all forms of observation and monitoring have we ourselves become collateral damage here? Not only are we handing our digital assets to the surveillance behemoths, but we also don't really understand what assets we are handing over. We also don't have any practical visibility as to what happens to this data, and whether or not the data will be used in contexts that are hostile to our individual interests.

Geoff Huston concurs with Paul Vixie's recent talk (Thanks to Keith Howanitz.)

Of course, the $8 blue check that [Elon] Musk insists is "the great leveler" is already the great leveler... for scammers. There's already someone who bought their $8 bluecheck, changed their name to Twitter and seemed to have successfully fooled people... with a crypto scam. You know, the thing Musk swore the new blue check system would eliminate.
Mike Masnick

Remember, Trustcor isn't just in Firefox's root of trust – it's in the roots of trust for Chrome (Google) and Safari (Apple). All the major browser vendors were supposed to investigate this company and none of them disqualified it, despite all the vivid red flags.

Worse, [Joel] Reardon and [Serge] Egelman say they notified all three companies about the problems with Trustcor seven months ago, but didn't hear back until they published their findings publicly on Tuesday.

There are 169 root certificate authorities in Firefox, and comparable numbers in the other major browsers. It's inconceivable that you could personally investigate each of these and determine whether you want to trust it. We rely on the big browser vendors to do that work for us. We start with: "Assume the browser vendors are careful and diligent when it comes to trusting companies on our behalf." We assume that these messy, irregular companies are perfectly spherical cows of uniform density on a frictionless surface.

Cory Doctorow reports on a Washington Post article based on this thread

to post comments

Trustcor

Posted Nov 10, 2022 1:02 UTC (Thu) by rgmoore (✭ supporter ✭, #75) [Link]

If I'm reading the article correctly, the big worry about a company like Trustcor isn't that Google, Apple, and Mozilla somehow missed obvious red flags when vetting it. The big worry is that they correctly identified it as a problem, but the US government leaned on them to approve it anyway. Mistakes can and do happen, but we can learn from them and try to do better in the future. You can't really do the same thing about being pressured by the US government.

Security quotes of the week

Posted Nov 10, 2022 14:18 UTC (Thu) by ejr (subscriber, #51652) [Link] (2 responses)

Combining the first and last quotes: Things like letsencrypt hide the intermediate traffic between two entities that now *think* there's some trust relationship. There isn't. A hijacked domain with a letsencrypt cert looks just as trustworthy as the original... And no monitoring between the endpoints can identify a definite issue. Ain't that fun? Sure, heuristically the sudden changes in transfer sizes and end-point addresses is interesting, but so are a zillion other oddities that occur on networks.

And purely on the first, I once had someone at LexisNexis point out that there are few other countries where their business of slurping in *all* information about *everyone* would be legal. People think of Google, Facebook (see the relevant Black Mirror episode), etc., but they're nothing compared to LexusNexis. All public records down to changes of address. Many private records offered up for background checks, credit checks, etc. The others have information given for electronic transactions; LN also has the information on real, physical things. Luckily, they have so much that it's very, very difficult to mine / query.

Security quotes of the week

Posted Nov 10, 2022 14:47 UTC (Thu) by esemwy (guest, #83963) [Link] (1 responses)

On the first, it’s worse yet on large corporate networks. It’s SOP to subvert the client-server certificate relationship. Clients are made to trust anything the corporate SSL proxy is willing to pass, whether it’s verifying certificates or not.

On the second, its not corporations or the government. It’s corporations *and* the government. Facebook, Google, and LexisNexis freely share with the government. That’s why their operation has been allowed to stay legal.

Security quotes of the week

Posted Nov 11, 2022 0:32 UTC (Fri) by ejr (subscriber, #51652) [Link]

I'm less worried about the corporate security boundaries than the blind trust in some icon somewhere (pun on definition of icon fully intended). I use letsencrypt, but I have no illusions about its trustworthiness. I just want PFS for the occasional times I need to convey a password, aware of the implied limitations of PFS. Things change once I'm in a secured and audited location.

And, yeah, it's not freely given always. Cases (afaik) have some nominal charge for the hours unless it's for the greater public good. Like stopping shootings. But that was a while ago.

Security quotes of the week

Posted Nov 10, 2022 17:10 UTC (Thu) by riking (subscriber, #95706) [Link]

> TrustCor’s most recent audit statements ([Standard] and [BR - TLS]) describe CA operations in Toronto, Ontario, Canada.
> PAG is listed as a licensed practitioner only in the USA.
> TrustCor’s CPS indicates the data centers are located in Phoenix.

This is exactly the kind of thing that's really hard to catch, because looking at each document in isolation it seems fine...

Security quotes of the week

Posted Nov 10, 2022 19:46 UTC (Thu) by flussence (guest, #85566) [Link] (1 responses)

Many people on this wavelength have already drawn parallels between the collapse of Twitter and of Freenode, but the latter scam was at least somewhat logically trying to sell products for money (VPN/bouncer/etc). Here there's just… a man-made disaster. It seems likely that a large part of documented recent human history is about to blip out of existence with no backups.

Security quotes of the week

Posted Jan 16, 2023 11:42 UTC (Mon) by immibis (subscriber, #105511) [Link]

Freenode wasn't really trying to sell products for money. It had a little advertising that was irrelevant to the actual problems.


Copyright © 2022, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds