{"id":570,"date":"2017-04-01T16:24:34","date_gmt":"2017-04-02T00:24:34","guid":{"rendered":"http:\/\/unmitigatedrisk.com\/?p=570"},"modified":"2017-04-09T20:22:44","modified_gmt":"2017-04-10T04:22:44","slug":"cas-and-ssl-and-phishing-oh-my","status":"publish","type":"post","link":"https:\/\/unmitigatedrisk.com\/?p=570","title":{"rendered":"CAs and SSL and Phishing Oh My!"},"content":{"rendered":"<p><a href=\"http:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2017\/04\/lionstigersbears.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"alignleft size-medium wp-image-579\" src=\"http:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2017\/04\/lionstigersbears-300x225.jpg\" alt=\"\" width=\"300\" height=\"225\" srcset=\"https:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2017\/04\/lionstigersbears-300x225.jpg 300w, https:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2017\/04\/lionstigersbears.jpg 400w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p><b><i>NOTE: <\/i><\/b><i><span style=\"font-weight: 400;\">This post reflects my personal beliefs and is not necessarily those of my employer Google, or Let\u2019s Encrypt where I am a member of their Technical Advisory Board.<\/span><\/i><\/p>\n<h1><span style=\"font-weight: 400;\">Introduction<\/span><\/h1>\n<p><span style=\"font-weight: 400;\">Recently Vincent <\/span><span style=\"font-weight: 400;\">from The SSL Store published a <a href=\"https:\/\/www.thesslstore.com\/blog\/lets-encrypt-paypal\/\">blog post<\/a> <\/span><span style=\"font-weight: 400;\">calling out Let\u2019s Encrypt for issuing certificates to domains that contain the world PayPal.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The TL;DR for his post is he believes that Let\u2019s Encrypt is enabling phishers by issuing them SSL certificates that contain the word \u201cPayPal\u201d and then refusing to revoke them when arbitrary third-parties ask them to.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">As a result of his post, several news sources have decided to write articles about how\u00a0&#8220;Let\u2019s Encrypt&#8221; is acting as an enabler of these Phishers [<a href=\"https:\/\/www.engadget.com\/2017\/03\/31\/when-the-s-in-https-also-stands-for-shady\/\">1<\/a>] [<a href=\"http:\/\/www.theinquirer.net\/inquirer\/news\/3007326\/lets-encrypt-has-issued-15-000-ssl-certificates-to-paypal-phishing-sites\">2<\/a>]<\/span><span style=\"font-weight: 400;\">.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Unfortunately, Vincent\u2019s post and the associated articles don\u2019t cover this in the most complete and balanced way so over my morning coffee today I decided to write this post to discuss the other side of the argument.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">If this is a topic that interests you please also check out the Let\u2019s Encrypt blog post where they talk about why they have taken<a href=\"https:\/\/letsencrypt.org\/2015\/10\/29\/phishing-and-malware.html\"> this position<\/a><\/span><span style=\"font-weight: 400;\">.<\/span><\/p>\n<h1><span style=\"font-weight: 400;\">Exploration<\/span><\/h1>\n<p><span style=\"font-weight: 400;\">Let\u2019s explore the opportunities CAs have to check for phishing, the tools they have available to them, the effectiveness of those tools, the consequences of this approach, how complete a solution based on the tools available to them would be and what the resulting experience would be for users.<\/span><\/p>\n<h2><span style=\"font-weight: 400;\">Opportunities<\/span><\/h2>\n<p><span style=\"font-weight: 400;\">The WebPKI\u2019s CAs role, historically, has been that of a Passport office, you present proof you control a domain, and possibly that you are an authorized member of an organization and you get a digital certificate that attests to that.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">This certificate could be valid for up to 1095 days. Once the certificate is issued the CA, largely speaking, has no natural opportunity to verify this information again. It is worth noting that this month the <a href=\"https:\/\/cabforum.org\/pipermail\/public\/2017-March\/010101.html\">CABForum voted to shorten this period to 825 days<\/a><\/span><span style=\"font-weight: 400;\">.<\/span><\/p>\n<h2><span style=\"font-weight: 400;\">Tools<\/span><\/h2>\n<p><span style=\"font-weight: 400;\">In the event a CA determines it made a mistake in the issuance of a certificate or has been notified by the subscriber they would like to see a certificate marked invalid, the tool they have available to them is called &#8220;revocation&#8221;.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The two types of revocation that are under the control of a Certificate Authority are called Certificate Revocation Lists and OCSP responses. The first is a like a phonebook of all known \u201crevoked\u201d certificates while the last is more like a lookup that it enables User Agents to ask the status of a particular set of certificates.<\/span><\/p>\n<h2><span style=\"font-weight: 400;\">Effectiveness<\/span><\/h2>\n<p><span style=\"font-weight: 400;\">Earlier we discussed the lifetime of certificates, this is important to understand because the <a href=\"http:\/\/www.domaintools.com\/content\/The_DomainTools_Report_Distribution_Malicious_Domain.pdf\">large majority of phishing sites do not start out as Phishing sites<\/a>, as such issuance time checks seldom net positive results.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">After issuance, this leaves you with periodic checks of the site, \u00a0third-party reports of phishing and relying on revocation checking as an enforcement mechanism. This is a recipie for failure, there are a few reasons for this, but one of the more significant is the general ineffectiveness\u00a0of revocation checking.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Revocation checking is the most taxing thing a CA does. This is because the revocation mechanisms available to them will result in every relying party contacting them to download\u00a0a OCSP response or CRL covering that certificate.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">As a result, OCSP has a tendency to be both slow and unreliable. This forced browsers to implement this check as a \u201csoft fail\u201d, in other words, if the connection times out or fails for some reason they assume the certificate as good. <\/span><\/p>\n<p><span style=\"font-weight: 400;\">To give that some context about <a href=\"https:\/\/twitter.com\/rmhrisk\/status\/828674790797963264\">8% of all revocation checks done by Firefox fail <\/a><\/span><span style=\"font-weight: 400;\">and the <a href=\"https:\/\/telemetry.mozilla.org\/new-pipeline\/dist.html#!cumulative=0&amp;end_date=2017-01-25&amp;keys=__none__!__none__!__none__&amp;max_channel_version=release%252F51&amp;measure=CERT_VALIDATION_HTTP_REQUEST_SUCCEEDED_TIME&amp;min_channel_version=null&amp;processType=*&amp;product=Firefox&amp;sanitize=1&amp;sort_keys=submissions&amp;start_date=2017-01-18&amp;table=0&amp;trim=1&amp;use_submission_date=0\">median response time is over 200ms<\/a><\/span><span style=\"font-weight: 400;\">. <\/span><\/p>\n<p><span style=\"font-weight: 400;\">As a result of this in 2012 Chrome, <a href=\"http:\/\/gs.statcounter.com\/)\">which is used by about 50% of all users<\/a><\/span><span style=\"font-weight: 400;\">, more-or-less <a href=\"https:\/\/www.imperialviolet.org\/2012\/02\/05\/crlsets.html\">disabled revocation checking except for exceptional circumstances<\/a><\/span><span style=\"font-weight: 400;\">.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">What this means is that revocation checking, even for its intended purpose, is far from an effective tool. Expanding its use to include protecting users from phishers would not improve its effectiveness and arguably it would (due to the infrastructure implications) make it even less reliable.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">It is also important to note that every wildcard certificate can be used for a hostname containing &#8220;<\/span><span style=\"font-weight: 400;\">PayPal\u201d without the CA ever being made aware, a good example is <\/span><a href=\"https:\/\/paypal.github.io\/\"><span style=\"font-weight: 400;\">https:\/\/paypal.github.io\/<\/span><\/a><span style=\"font-weight: 400;\"> which is protected by a wildcard certificate issued to Github. <\/span><\/p>\n<h2><span style=\"font-weight: 400;\">Consequences<\/span><\/h2>\n<p><span style=\"font-weight: 400;\">To understand the consequences of expanding the CAs role include protecting us from phishing we first need to understand what a certificate represents, or more importantly what it does not represent. It does not represent the content, it represents the host that is serving content and it is the content that &#8220;phishes&#8221;.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Today, in the age of cloud services, there is a good chance the host that is serving the content is a service operated by WordPress, or maybe Amazon\u2019s S3. These services allow users to sign up and post arbitrary content for free or very little money. <\/span><\/p>\n<p><span style=\"font-weight: 400;\">If we decide that revocation checking is the right tool to get phishing content off the web we would be saying a CA should revoke WordPress\u2019s certificate if one of it\u2019s users posted something someone reported as phishing content. That would, for the situations where revocation checking takes place and happens to work, take WordPress off the Internet. Is that what we want to happen?<\/span><\/p>\n<p><span style=\"font-weight: 400;\">If so, who is it we are asking to perform this task? There are <a href=\"https:\/\/social.technet.microsoft.com\/wiki\/contents\/articles\/37425.microsoft-trusted-root-certificate-program-participants-as-of-march-9-2017.aspx\">well over 400 CAs in the Microsoft Root Program<\/a> <\/span><span style=\"font-weight: 400;\">do we believe these are the right organizations to be policing the internet for the appropriateness of content?<\/span><\/p>\n<p><span style=\"font-weight: 400;\">If so what criteria should they use to do so and what do we do if they abuse this censorship role?<\/span><\/p>\n<h2><span style=\"font-weight: 400;\">Completeness<\/span><\/h2>\n<p><span style=\"font-weight: 400;\">It is easy to say that a CA should not issue a certificate if it contains the word \u201cPayPal\u201d. I could even see an argument that those that would be hurt by such a rule, for example, <\/span><a href=\"http:\/\/www.paypalsucks.com\/\"><span style=\"font-weight: 400;\">http:\/\/www.PayPalSucks.com<\/span><\/a><span style=\"font-weight: 400;\">\u00a0and (a theoretical) PayPalantir.com are an acceptable loss.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">This would, however not catch homoglyphs like when a Cyrillic \u201ca\u201d is used instead of the latin \u201ca\u201d which would very likley require a manual review of the name and content to determine the\u00a0intent of the domain owner which is near impossible to do with any level of accuracy or fairness.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Even with that, what about ING, as one of the world&#8217;s largest banks, they too are commonly phished, should a CA be able to issue a certificate to <\/span><a href=\"https:\/\/www.fishing.com\"><span style=\"font-weight: 400;\">https:\/\/www.fishing.com<\/span><\/a><span style=\"font-weight: 400;\">. And if they do and the issuing CA receives a complaint that it is Phishing ING what should they do?<\/span><\/p>\n<p><span style=\"font-weight: 400;\">And what about global markets and languages? In Romania there is a company called <a href=\"https:\/\/opencorporates.com\/companies\/ro\/14476633\">Amazon<\/a> <\/span><span style=\"font-weight: 400;\">that is a cleaning company, should anyone be able to request their website be revoked because it contains the word Amazon?<\/span><\/p>\n<p><span style=\"font-weight: 400;\">If we promote the CA to content police, how do we do so in a complete way?<\/span><\/p>\n<h2><span style=\"font-weight: 400;\">User Experience<\/span><\/h2>\n<p><span style=\"font-weight: 400;\">With CAs acting as the content police, what would a user see when they encounter a revoked site? While it varies browser to browser the experience is almost always a blocking \u201cinterstitial\u201d, for example:<\/span><\/p>\n<table>\n<tbody>\n<tr>\n<td>\u00a0<a href=\"http:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2017\/04\/chrome-revoked.png\"><img decoding=\"async\" class=\"alignleft size-medium wp-image-571\" src=\"http:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2017\/04\/chrome-revoked-300x297.png\" alt=\"chrome revoked\" width=\"275\" srcset=\"https:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2017\/04\/chrome-revoked-300x297.png 300w, https:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2017\/04\/chrome-revoked-150x150.png 150w, https:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2017\/04\/chrome-revoked-768x761.png 768w, https:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2017\/04\/chrome-revoked-624x618.png 624w, https:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2017\/04\/chrome-revoked.png 892w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/a><\/td>\n<td><a href=\"http:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2017\/04\/firefox-revoked.png\"><img decoding=\"async\" class=\"alignleft size-medium wp-image-572\" src=\"http:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2017\/04\/firefox-revoked-300x288.png\" alt=\"firefox revoked\" width=\"275\" srcset=\"https:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2017\/04\/firefox-revoked-300x288.png 300w, https:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2017\/04\/firefox-revoked-768x736.png 768w, https:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2017\/04\/firefox-revoked-624x598.png 624w, https:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2017\/04\/firefox-revoked.png 891w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/a><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><span style=\"font-weight: 400;\"><br \/>\nIf you look closely you will see these\u00a0are not screens that you can bypass, revoked sites are effectively removed from the internet.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">This is in contrast to <\/span><a href=\"https:\/\/safebrowsing.google.com\/\"><span style=\"font-weight: 400;\">Safe Browsing<\/span><\/a><span style=\"font-weight: 400;\"> and <\/span><a href=\"https:\/\/en.wikipedia.org\/wiki\/Microsoft_SmartScreen\"><span style=\"font-weight: 400;\">Smartscreen<\/span><\/a><span style=\"font-weight: 400;\"> which were designed for this particular problem set and therefore provide the user a chance to visit the site after a contextually relevant warning:<\/span><\/p>\n<table>\n<tbody>\n<tr>\n<td>\u00a0<a href=\"http:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2017\/04\/SafeBrowsing.png\"><img decoding=\"async\" class=\"alignleft size-medium wp-image-573\" src=\"http:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2017\/04\/SafeBrowsing-300x214.png\" alt=\"SafeBrowsing\" width=\"275\" srcset=\"https:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2017\/04\/SafeBrowsing-300x214.png 300w, https:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2017\/04\/SafeBrowsing-768x547.png 768w, https:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2017\/04\/SafeBrowsing-624x445.png 624w, https:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2017\/04\/SafeBrowsing.png 978w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/a><\/td>\n<td><a href=\"http:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2017\/04\/smartscreen.png\"><img decoding=\"async\" class=\"alignleft size-medium wp-image-574\" src=\"http:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2017\/04\/smartscreen-300x199.png\" alt=\"smartscreen\" width=\"275\" srcset=\"https:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2017\/04\/smartscreen-300x199.png 300w, https:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2017\/04\/smartscreen-768x509.png 768w, https:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2017\/04\/smartscreen-624x413.png 624w, https:\/\/unmitigatedrisk.com\/wp-content\/uploads\/2017\/04\/smartscreen.png 981w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/a><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h1><span style=\"font-weight: 400;\">Conclusion<\/span><\/h1>\n<p><span style=\"font-weight: 400;\">I hope you see from the above that relying on Certificate Authorities as content police as a means to protect users from phishers a bad idea, at a minimum, it would be:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Ineffective,<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Incomplete,<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Unmanageable,<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">and Duplicative.<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">But more importantly it would be establishing a large loosely managed group as the de-facto content censors on the internet and as Steven Spielberg said, there is a fine line between censorship, good taste, and moral responsibility.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">So what should CAs do about phishing then? It is my position they should check the Google Safe Browsing API prior to issuance (which by the way, Let\u2019s Encrypt does), and they should report Phishers to the Safe Browsing service if they encounter any. <\/span><\/p>\n<p><span style=\"font-weight: 400;\">It is also important to answer the question about what users should do to protect themselves from phishing. I understand the desire to say there is only one indicator they need to be worried about, it&#8217;s just not realistic. <\/span><\/p>\n<p><span style=\"font-weight: 400;\">When I talk to regular users I tell them to do three things, the first of which is to use an up-to-date and modern browser that uses Smart Screen or Safe Browsing. Second, you should only provide data to sites you know and only over SSL. And finally, try to only provide sites information when it was you initiated the exchange of information.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">P.S.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Thanks To <a href=\"https:\/\/twitter.com\/vtlynch\">Vincent Lynch <\/a><\/span><span style=\"font-weight: 400;\">and the others who were kind enough to proof this post before publishing.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; NOTE: This post reflects my personal beliefs and is not necessarily those of my employer Google, or Let\u2019s Encrypt where I am a member of their Technical Advisory Board. Introduction Recently Vincent from The SSL Store published a blog post calling out Let\u2019s Encrypt for issuing certificates to domains [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"footnotes":""},"categories":[1],"tags":[34,25,194,24,19],"class_list":["post-570","post","type-post","status-publish","format-standard","hentry","category-uncategorized","tag-crl","tag-ocsp","tag-phishing","tag-revocation","tag-x509"],"_links":{"self":[{"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=\/wp\/v2\/posts\/570","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=570"}],"version-history":[{"count":0,"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=\/wp\/v2\/posts\/570\/revisions"}],"wp:attachment":[{"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=570"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=570"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=570"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}