{"id":908,"date":"2024-11-30T20:44:25","date_gmt":"2024-12-01T04:44:25","guid":{"rendered":"https:\/\/unmitigatedrisk.com\/?p=908"},"modified":"2024-12-01T19:30:28","modified_gmt":"2024-12-02T03:30:28","slug":"another-ca-fails-the-turing-test","status":"publish","type":"post","link":"https:\/\/unmitigatedrisk.com\/?p=908","title":{"rendered":"Another CA Fails the Turing Test?"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">In a concerning development, yet another Certificate Authority (CA) has issued what is likely a man-in-the-middle (MITM) certificate\u2014something strictly prohibited by all root programs. This particular case is unique because the CA is trusted only by Microsoft, making the situation both frustratingly familiar and uniquely problematic. Details are emerging in this <a href=\"https:\/\/bugzilla.mozilla.org\/show_bug.cgi?id=1934361\">Bugzilla thread<\/a>.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">A Familiar Pattern<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">Back in 2011, I wrote about Microsoft\u2019s trust in government-run CAs and the inherent risks (<a href=\"https:\/\/unmitigatedrisk.com\/?p=181#:~:text=Government%20of%20Brazil%2C%20Autoridade%20Certificadora%20Raiz%\">read here<\/a>). More than a decade later, it\u2019s clear little has changed. Browser distrust events happen with disappointing regularity\u2014roughly every 1.25 years, according to my analysis (<a href=\"https:\/\/unmitigatedrisk.com\/?p=850\">source<\/a>). While MITM certificate issuance is far rarer, it\u2019s far more serious, and a disturbing trend is evident: Many of the CAs responsible are government-run or affiliated.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Why This Matters to You<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">For Windows users, this is particularly relevant. Windows browsers like Edge (and others) rely on the Microsoft Root Program, which has unfortunately historically been overly permissive and slow to respond to incidents. You can learn more about the program and its requirements <a href=\"https:\/\/learn.microsoft.com\/en-us\/security\/trusted-root\/\">here<\/a>. In the recent past, I can\u2019t recall a CA responsible for willfully issuing an MITM certificate surviving, but the the timeline for Microsoft\u2019s response is unclear. That said, when Microsoft does act, their AutoRoot Update feature\u2014which I was the product manager for in the early 2000s\u2014allows them to respond swiftly.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In the meantime, you can protect yourself by identifying and distrusting the offending certificate. Enterprises, in particular, can take a proactive stance by using the Microsoft distrust store. Through group policy, IT administrators can preemptively distrust the problematic CA across their organization, mitigating the risk before Microsoft formally acts.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">The Lack of Technical Controls<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">It\u2019s worth noting there are no technical controls that inherently prevent CAs from issuing MiTM certificates (though some browsers do have technical controls for some classes of misissuance). Instead, the WebPKI ecosystem relies on Certificate Transparency (CT) logs and a dedicated community of people closely monitoring CA issuance for violations of requirements. In a way, this incident serves as a smoke test for the system\u2014but when it comes to these MITM certificates, it\u2019s an awfully expensive test, with significant risks both for users of the web and reputational risks for the root programs, as well as questions about the trustworthiness of the WebPKI in general.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Predictable Chaos<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">If you\u2019re following this story, keep an eye on the <a href=\"https:\/\/bugzilla.mozilla.org\/show_bug.cgi?id=1934361\">Bugzilla thread<\/a>. Based on past experience, I\u2019d wager the CA in question will bungle its incident response. MITM certificate issuance often reflects systemic issues, and such organizations typically don\u2019t have the maturity to handle these crises well.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If this topic interests you, here\u2019s some further reading:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/unmitigatedrisk.com\/?p=881\">Problem report handling times for CAs<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/unmitigatedrisk.com\/?p=702#comment-395398\">Why WebPKI CAs exist<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/unmitigatedrisk.com\/?p=847\">Why we trust them<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/certificatetransparency.dev\">Certificate Transparency<\/a><\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">For a deeper dive, here\u2019s a <a href=\"https:\/\/docs.google.com\/presentation\/d\/12zTOSd9cpG5VnzauP6Rd394gQmgXGK6jPbKcb_TOQGI\/edit#slide=id.g2f3c7550f27_1_91\">class I run<\/a> on the topic of WebPKI incident response and how they\u2019re (mis)handled.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Lessons Unlearned<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">While it\u2019s comforting to know mechanisms like Certificate Transparency exist to catch these incidents, the recurring nature of these failures raises the question: Are we doing enough to hold CAs accountable?<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Trust in the web depends on the reliability of its foundational systems. It\u2019s time we demand higher standards from the organizations entrusted with securing our online world. Until then, stay informed, protect yourself, and let\u2019s hope the next CA at least manages to pass the &#8220;Turing Test.&#8221;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>In a concerning development, yet another Certificate Authority (CA) has issued what is likely a man-in-the-middle (MITM) certificate\u2014something strictly prohibited by all root programs. This particular case is unique because the CA is trusted only by Microsoft, making the situation both frustratingly familiar and uniquely problematic. Details are emerging in this Bugzilla thread. A Familiar [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"footnotes":""},"categories":[3,4],"tags":[],"class_list":["post-908","post","type-post","status-publish","format-standard","hentry","category-security","category-thoughts"],"_links":{"self":[{"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=\/wp\/v2\/posts\/908","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=908"}],"version-history":[{"count":0,"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=\/wp\/v2\/posts\/908\/revisions"}],"wp:attachment":[{"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=908"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=908"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/unmitigatedrisk.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=908"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}