Perimeter
7/30/2009
12:26 PM
Sara Peters
Sara Peters
Commentary
Connect Directly
Twitter
RSS
E-Mail
50%
50%

Black Hat, Day One: Rationalizing And Reinforcing My Pessimistic World View

When I arrived in Las Vegas, I already smoldered and grumbled about the facts that online trust mechanisms are untrustworthy, and that browsers' fundamental weaknesses persist despite the fact that better browsers would make an incalculable impact on overall Web security. Yesterday's sessions simply added more kindling to the fire.

When I arrived in Las Vegas, I already smoldered and grumbled about the facts that online trust mechanisms are untrustworthy, and that browsers' fundamental weaknesses persist despite the fact that better browsers would make an incalculable impact on overall Web security. Yesterday's sessions simply added more kindling to the fire.The charmingly dreadlocked Moxie Marlinspike delivered a fascinating presentation in which he showed us four new ways his SSL Sniff and SSL Strip tools could be suped up to make SSL certificates less trustworthy than ever.

Several months ago Marlinspike created SSL Strip, a tool that exploits a Web vulnerability and behaves as a man in the middle, slipping into the middle of an https redirect. So when a user leaves an http session and thinks they're being sent to an https session, the attacker has actually sent them somewhere else. The user thinks they've begun operating in a secure session, but in actuality they never made it to the legitimate SSL-encrypted site. A legitimately secure site and a "stripped" site were almost indistinguishable.

Yesterday Marlinkspike showed a demo in which the legitimate and exploited sites were entirely indistinguishable. Marlinspike showed how to overcome even the two significant hurdles that would, theoretically, prevent his attacks -- software updates and OCSP (the Online Certificate Status Protocol). The update problem was sidestepped by going after the update server itself--thereby achieving the access privileges necessary to make updates silent. The OCSP trouble required different trickery that I won't get too deeply into here, but suffice it to say that all it required was to send a milquetoast error message -- "try again later."

The heart of the problem though is the X.509 standard, which Marlinspike called "a total nightmare" and security rockstar Dan Kaminsky later called "remarkably fragile." Ultimately X.509 is fraught with ambiguity, which means that everyone is implementing their crypto somewhat differently -- and that makes life complicated for both browsers and certifying authorities (CAs). They can't lower the boom on poor, insecure configurations without running the risk of demolishing the authentication systems of many, many, many, sites.

The good news is that, according to Kaminsky, browser vendors, CAs and security researchers alike are working together to start repairing these problems -- first trying to patch up the X.509 standard, then deciding upon a better authentication method (possibly leveraging DNSSEC), then (fingers crossed) figuring out how to move from X.509 to a brave new world.

In entirely unrelated news...Dmitri Alperovitch described the nationalistic yet capitalistic mindset of Russian organized crime in a clearer way than I'd heard it put before: Money is the motive. Nationalism is the rationalization.

Sara Peters is senior editor at Computer Security Institute. Special to Dark Reading. Sara Peters is Senior Editor at Dark Reading and formerly the editor-in-chief of Enterprise Efficiency. Prior that she was senior editor for the Computer Security Institute, writing and speaking about virtualization, identity management, cybersecurity law, and a myriad ... View Full Bio

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Flash Poll
Current Issue
Cartoon
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-6306
Published: 2014-08-22
Unspecified vulnerability on IBM Power 7 Systems 740 before 740.70 01Ax740_121, 760 before 760.40 Ax760_078, and 770 before 770.30 01Ax770_062 allows local users to gain Service Processor privileges via unknown vectors.

CVE-2014-0232
Published: 2014-08-22
Multiple cross-site scripting (XSS) vulnerabilities in framework/common/webcommon/includes/messages.ftl in Apache OFBiz 11.04.01 before 11.04.05 and 12.04.01 before 12.04.04 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, which are not properly handled in a (1)...

CVE-2014-3525
Published: 2014-08-22
Unspecified vulnerability in Apache Traffic Server 4.2.1.1 and 5.x before 5.0.1 has unknown impact and attack vectors, possibly related to health checks.

CVE-2014-3563
Published: 2014-08-22
Multiple unspecified vulnerabilities in Salt (aka SaltStack) before 2014.1.10 allow local users to have an unspecified impact via vectors related to temporary file creation in (1) seed.py, (2) salt-ssh, or (3) salt-cloud.

CVE-2014-3587
Published: 2014-08-22
Integer overflow in the cdf_read_property_info function in cdf.c in file through 5.19, as used in the Fileinfo component in PHP before 5.4.32 and 5.5.x before 5.5.16, allows remote attackers to cause a denial of service (application crash) via a crafted CDF file. NOTE: this vulnerability exists bec...

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Three interviews on critical embedded systems and security, recorded at Black Hat 2014 in Las Vegas.