{"type":"rich","version":"1.0","author_name":"npub1f2nvlx49er5c7sqa43src6ssyp6snd4qwvtkwm5avc2l84cs84esecrwet","author_url":"https://nostr.ae/npub1f2nvlx49er5c7sqa43src6ssyp6snd4qwvtkwm5avc2l84cs84esecrwet","provider_name":"njump","provider_url":"https://nostr.ae","html":"📅 Original date posted:2013-12-08\n📝 Original message:On Sun, Dec 8, 2013 at 12:40 PM, Drak \u003cdrak at zikula.org\u003e wrote:\n\u003e Let me clarify. SSL renders BGP redirection useless because the browser\n\u003e holds the signatures of CA's it trusts: an attacker cannot spoof a\n\u003e certificate because it needs to be signed by a trusted CA: that's the point\n\u003e of SSL, it encrypts and proves identity, the latter part is what thwarts\n\u003e MITM. If there was an MITM the browser screams pretty loudly about it with a\n\u003e big threat warning interstitial.\n\nSadly this isn't true: There are (many) CAs which will issue a\ncertificate (apparently sometime within minutes, though last\ncertificate I obtained took a couple hours total) to anyone who can\nrespond to http (not https) requests on behalf of the domain from the\nperspective of the CA.\n\nThis means you can MITM the site, pass all traffic through except the\nHTTP request from the CA, and start intercepting once the CA has\nsigned your certificate. This works because the CA does nothing to\nverify identity except check that the requester can control the site.\n\nIf you'd like to me to demonstrate this attack for you I'd be willing—\nI can provide a proxy that passes on :80 and :443, run your traffic\nthrough it and I'll get a cert with your domain name.\n\nI'm sorry for the tangent here— I think this sub-discussion is really\nunrelated to having Bitcoin.org behind SSL— but \"someone is wrong on\nthe internet\", and its important to know that SSL hardly does anything\nto reduce the need to check the offline signatures on the binaries."}
