Friday, August 12. 2011OpenLeaks doing strange things with SSLComments
Display comments as
(Linear | Threaded)
I'm not saying that i trust openleaks technicians, but trusting SSL for something like this today is the worst mistake you can ever make. SSL is broken, for too many years, stop talking like is a good thing because it only adds a security sense that is not there.
no, ssl is not that broken, it works pretty well on most browser.
but the ssl certificate chain management is broken in a "human" way : too many authorities can sign too many domain names with too few controls (see the conference "is ssliverse a safe place" from EFF at the CCC Conference) but yes, the point of this article stays : openleaks don't know ssl well, which make me fear for the security of submitted material ...
Ich glaube Du hast das Problem nicht ganz verstanden:
Sie hatten ein "teures" Cert. Sie haben es nur nicht korrekt installiert.
I don't agree that the message "Before submitting anything verify that the fingerprints of the SSL certificate match!" is completely useless. Seein a matching fingerprint certainly doesn't mean that the line is secure as it might be changed. But seeing a non-matching fingerprint warns me that the connection is rigged. This actually happend to me!
https://twitter.com/#!/lostgen/status/101956044925845504
Lostgen, if your connection were compromised, a smart attacker would have changed the fingerprint as well. This implies you will never see a non-matching fingerprint when your connection is compromised by a man-in-the-middle attack.
I'd suggest to armor-sign the fingerprint with PGP (this will even be ok over the very same ssl-connection) - as long as you have verified the key before at least once. Also, you might want to try perspectives (http://www.heise.de/security/artikel/Perspectives-und-Co-271022.html). It will cross-check the certificate you see with recently-seen certificates by you and others. |
About meYou can find my web page with links to my work as a journalist at https://hboeck.de/.
You may also find my newsletter about climate change and decarbonization technologies interesting. Hanno Böck mail: hanno@hboeck.de Hanno on Mastodon Impressum Show tagged entries |
Tracked: Aug 16, 13:54
Tracked: Aug 17, 14:40