Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Perimeter

7/30/2009
12:26 PM
Sara Peters
Sara Peters
Commentary
Connect Directly
Twitter
RSS
E-Mail
50%
50%

Black Hat, Day One: Rationalizing And Reinforcing My Pessimistic World View

When I arrived in Las Vegas, I already smoldered and grumbled about the facts that online trust mechanisms are untrustworthy, and that browsers' fundamental weaknesses persist despite the fact that better browsers would make an incalculable impact on overall Web security. Yesterday's sessions simply added more kindling to the fire.

When I arrived in Las Vegas, I already smoldered and grumbled about the facts that online trust mechanisms are untrustworthy, and that browsers' fundamental weaknesses persist despite the fact that better browsers would make an incalculable impact on overall Web security. Yesterday's sessions simply added more kindling to the fire.The charmingly dreadlocked Moxie Marlinspike delivered a fascinating presentation in which he showed us four new ways his SSL Sniff and SSL Strip tools could be suped up to make SSL certificates less trustworthy than ever.

Several months ago Marlinspike created SSL Strip, a tool that exploits a Web vulnerability and behaves as a man in the middle, slipping into the middle of an https redirect. So when a user leaves an http session and thinks they're being sent to an https session, the attacker has actually sent them somewhere else. The user thinks they've begun operating in a secure session, but in actuality they never made it to the legitimate SSL-encrypted site. A legitimately secure site and a "stripped" site were almost indistinguishable.

Yesterday Marlinkspike showed a demo in which the legitimate and exploited sites were entirely indistinguishable. Marlinspike showed how to overcome even the two significant hurdles that would, theoretically, prevent his attacks -- software updates and OCSP (the Online Certificate Status Protocol). The update problem was sidestepped by going after the update server itself--thereby achieving the access privileges necessary to make updates silent. The OCSP trouble required different trickery that I won't get too deeply into here, but suffice it to say that all it required was to send a milquetoast error message -- "try again later."

The heart of the problem though is the X.509 standard, which Marlinspike called "a total nightmare" and security rockstar Dan Kaminsky later called "remarkably fragile." Ultimately X.509 is fraught with ambiguity, which means that everyone is implementing their crypto somewhat differently -- and that makes life complicated for both browsers and certifying authorities (CAs). They can't lower the boom on poor, insecure configurations without running the risk of demolishing the authentication systems of many, many, many, sites.

The good news is that, according to Kaminsky, browser vendors, CAs and security researchers alike are working together to start repairing these problems -- first trying to patch up the X.509 standard, then deciding upon a better authentication method (possibly leveraging DNSSEC), then (fingers crossed) figuring out how to move from X.509 to a brave new world.

In entirely unrelated news...Dmitri Alperovitch described the nationalistic yet capitalistic mindset of Russian organized crime in a clearer way than I'd heard it put before: Money is the motive. Nationalism is the rationalization.

Sara Peters is senior editor at Computer Security Institute. Special to Dark Reading. Sara Peters is Senior Editor at Dark Reading and formerly the editor-in-chief of Enterprise Efficiency. Prior that she was senior editor for the Computer Security Institute, writing and speaking about virtualization, identity management, cybersecurity law, and a myriad ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
When It Comes To Security Tools, More Isn't More
Lamont Orange, Chief Information Security Officer at Netskope,  1/11/2021
US Capitol Attack a Wake-up Call for the Integration of Physical & IT Security
Seth Rosenblatt, Contributing Writer,  1/11/2021
IoT Vendor Ubiquiti Suffers Data Breach
Dark Reading Staff 1/11/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
2020: The Year in Security
Download this Tech Digest for a look at the biggest security stories that - so far - have shaped a very strange and stressful year.
Flash Poll
Assessing Cybersecurity Risk in Today's Enterprises
Assessing Cybersecurity Risk in Today's Enterprises
COVID-19 has created a new IT paradigm in the enterprise -- and a new level of cybersecurity risk. This report offers a look at how enterprises are assessing and managing cyber-risk under the new normal.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-25533
PUBLISHED: 2021-01-15
An issue was discovered in Malwarebytes before 4.0 on macOS. A malicious application was able to perform a privileged action within the Malwarebytes launch daemon. The privileged service improperly validated XPC connections by relying on the PID instead of the audit token. An attacker can construct ...
CVE-2021-3162
PUBLISHED: 2021-01-15
Docker Desktop Community before 2.5.0.0 on macOS mishandles certificate checking, leading to local privilege escalation.
CVE-2021-21242
PUBLISHED: 2021-01-15
OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, there is a critical vulnerability which can lead to pre-auth remote code execution. AttachmentUploadServlet deserializes untrusted data from the `Attachment-Support` header. This Servlet does not enforce any authentication or a...
CVE-2021-21245
PUBLISHED: 2021-01-15
OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, AttachmentUploadServlet also saves user controlled data (`request.getInputStream()`) to a user specified location (`request.getHeader("File-Name")`). This issue may lead to arbitrary file upload which can be used to u...
CVE-2021-21246
PUBLISHED: 2021-01-15
OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, the REST UserResource endpoint performs a security check to make sure that only administrators can list user details. However for the `/users/` endpoint there are no security checks enforced so it is possible to retrieve ar...