Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Businesses (and governments) can legitimately buy root keys that allow MITMing any SSL connection or they could just be a CA themselves (any CA can MITM the whole internet).

Here's the best talk I know of this subject: BlackHat USA 2011: SSL And The Future Of Authenticity: http://www.youtube.com/watch?v=Z7Wl2FW2TcA



I find this hard to believe.

"Businesses (and governments) can legitimately buy root keys that allow MITMing any SSL connection"

A business can buy their own SSL keys, but to MITM any SLL connection those keys would have to be trusted and installed at both ends of the connection and used to generate the SSL session key.

"any CA can MITM the whole internet"

Again, the CA's keys would have to be trusted and installed by the communicating parties.

Or have I misunderstood your point?


You did not misunderstand me, but you misunderstand how SSL in the context of HTTP is used and what CAs offer for sale. Please see the video I linked in my original post.


I don't have the time or opportunity to watch a 50 minute video right now, but I found a summary of the talk on the presenter's blog [1]. Interesting stuff! He references a paper [2] that discusses a "compelled assistance" attach, where a government can use the law to compel a CA to hand-over a certificate that would certainly be usable for a MITM attack. Bruce Schneier also mentioned this [3].

But this is far from "Businesses (and governments) can legitimately buy root keys that allow MITMing any SSL connection". Businesses can't invoke CALEA (or the UK RIPA[4] law, since we're talking about UK government surveillance) - only governments can do that. And the keys are not really being sold or bought. And I don't see how a government could compel a CA in a different legal jurisdiction anyway.

"any CA can MITM the whole internet"

No. A CA has access to keys that can be used to MITM a connection that is secured by keys issued by them. Thats not the "whole internet".

[1] http://blog.thoughtcrime.org/ssl-and-the-future-of-authentic... [2] http://files.cloudprivacy.net/ssl-mitm.pdf [3] http://www.schneier.com/blog/archives/2010/04/man-in-the-mid... [4] http://en.wikipedia.org/wiki/Key_disclosure_law#United_Kingd...


> And I don't see how a government could compel a CA in a different legal jurisdiction anyway.

Think Black Hawks and men in black suits.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: