• 0 Posts
  • 21 Comments
Joined 2 years ago
cake
Cake day: July 22nd, 2023

help-circle


  • The 3B was like peak RPi though. Nowadays unless you need the GPIO or the low power or form factor, it’s not worth it at all. You can get low-spec 3-5 year old off-lease office desktops for roughly the same price point as a top end RPi now, and they are commonplace and easily found in the secondary market.

    Hell I just bought a really clean Ryzen 5 3500 laptop for $200. Only had 8GB mem and a paltry NVMe but these are cheap upgrades if needed.







  • You are missing half the purpose of PKI. Identity is equally, if not more, as important as encryption.

    Who gives a shit if your password is encrypted if somebody intercepts DNS and sends yourbank.com and makes it go to their own server that’s hosting a carbon-copy of the homepage to collect passwords?

    And DNS isn’t the only attack vector for this. It can be done at the IP level by attacks that spoof BGP. It can be done by sticking a single-board computer in a trashcan at a subway stop. Have it broadcast a ton of well-known SSIDs and a ton of phones in the area will auto connect to it and can intercept traffic. Hell, if not for trusted CAs, it’d be very easy to just MITM all the HTTPS traffic anyway.

    In reality, you would tofu the first website you went to and not know if it got intercepted or if they just rotated keys (which is also a common security practice and is handled by renewing certificates and part of the reason why publicly-issued CAs are trending down the life of certificates and it’s not a big deal for admins because of easy automation technology. HSTS and cert pinning is more of a PITA but really barely any effort when you consider the benefits of those).

    Now, what certificates don’t protect, nor claim to protect, is typosquatting. If you instead go to yorbank.com, that’s on you, and protecting you from a malicious site that happened to buy it is the job for host-based security, web filters, and NGFWs.


  • But you only really need one to say it’s authentic. There are levels of validation that require different levels of effort. Domain Validation (DV) is the most simple and requires that you prove you own the domain, which means making a special domain record for them to validate (usually a long string that they provide over their HTTPS site), or by sending an email to the registered domain owner from their WHOIS record. Organization Validation (OV) and extended verification (EV) are the higher tiers, and usually require proof of business ownership and an in-person interview, respectively.

    Now, if you want to know if the site was compromised or malicious, that’s a different problem entirely. Certificates do not and cannot serve that function, and it’s wrong to place that role on CAs. That is a security and threat mitigation problem and is better solved by client-based applications, web filtering services, and next-gen firewalls, that use their own reputation databases for that.

    A CA is not expected to prevent me from hosting rootkits. Doesn’t matter if my domain is rootkits-are.us or totallylegitandsafe.net. It’s their job to make sure I own those domains. Nothing more. For a DV cert at least.

    Public key cryptography, and certificates in particular, are an amazing system. They don’t need to be scrapped because there’s a ton of misunderstanding as to its role and responsibilities.


  • Yeah, except you aren’t supposed to TOFU.

    Literally everybody does SSH wrong. The point of host keys is to exchange them out-of-band so you know you have the right host on the first connection.

    And guess what certificates are.

    Also keep in mind that although MS and Apple both publish trusted root lists, Mozilla is also one of, if not the, biggest player. They maintain the list of what ultimately gets distributed as ca-certificates in pretty much every Linux distro. It’s also the source of the Python certifi trusted root bundle, that required by requests, and probably makes its way into every API script/bot/tool using Python (which is probably most of them).

    And there’s literally nothing stopping you from curating your own bundle or asking people to install your cert. And that takes care of the issue of TOFU. The idea being that somebody that accepts your certificate trusts you to verify that any entity using a certificate you attach your name to was properly vetted by you or your agents.

    You are also welcome to submit your CA to Mozilla for consideration on including it on their master list. They are very transparent about the process.

    Hell, there’s also nothing stopping you from rolling a CA and using certificates for host and client verification on SSH. Thats actually preferable at-scale.

    A lot of major companies also use their own internal CA and bundle their own trusted root into their app or hardware (Sony does this with PlayStation, Amazon does this a lot of AWS Apps like workspaces, etc)

    In fact, what you are essentially suggesting is functionally the exact same thibg as self-signed certificates. And there’s absolutely (technically) nothing wrong with them. They are perfectly fine, and probably preferable for certain applications (like machine-to-machine communication or a closed environment) because they expire much longer than the 1yr max you can get from most public CAs. But you still aren’t supposed to TOFU them. That smacks right in the face of a zero-trust philosophy.

    The whole point of certificates is to make up for the issue of TOFU by you instead agreeing that you trust whoever maintains your root store, which is ultimately going to be either your OS or App developer. If you trust them to maintain your OS or essential app, then you should also trust them to maintain a list of companies they trust to properly vet their clientele.

    And that whole process is probably the number one most perfect example of properly working, applied, capitalism. The top-level CAs are literally selling honesty. Fucking that up has huge business ramifications.

    Not to mention, if you don’t trust Bob’s House of Certificate’s, there’s no reason you can’t entrust it from your system. And if you trust Jimbo’s Certificate Authority, you are welcome to tell your system to accept certificates they issue.




  • But tons of stuff would have to get sync’s every time you connect your phone. Better to have them cached, encrypted at rest, decrypted by key stored in the phone, and just do a diff-sync.

    This should be very easily possible with CarPlay and Android Auto. I have no idea if it does or not. But as Apple and Android both control both their respective app and the OS of the attached phone, there’s no reason it can’t (and even pre-compile diff packages for known cars, or expire and purge both sides after X days without a connection)

    That may not be true for regular old Bluetooth though…which likely has more to gain in performance from caching the resources due to BTs limited throughput, but also has to conform to standards.


  • Seriously, these cases seem like giant nothingburgers.

    Did you expect that your car wouldn’t have your text message when it’s displaying it on the screen or reading it out loud?

    Now, is there malicious intent? Can they be retrieved by technicians at the dealership if your phone isn’t plugged in? Is it forwarding them back to Honda Corporate or Zuck himself? If so, that’s a significant problem that would probably belong to Android Auto and Apple CarPlay…they should be storing them encrypted and only be able to decrypt them when the phone is connected. But I don’t see any mention of that in the article.




  • “Lifecycle” is not an apple specific thing. Literally everything has a lifecycle that makes the device obsolete/unsupported before it’s useful age is up.

    Technology in phones (primarily SoCs, batteries, and displays) moves faster then other categories, leading to the one year generations, but again, that’s something every brand does. It’s insane to suggest that companies continue to maintain old platforms that are in comparatively few pockets against discovered security vulnerabilities or leveraging new features beyond the capabilities of their hardware.

    iPhone 8 is now nearly six years old and supports IOS16, with rumors that it may support 17. I’d be surprised if it does, but that’s still a very impressive lifespan for a mobile phone.

    I understand apple hate but this is really one place where it’s undeserved.


  • I mean, I don’t know where you’re from, but at least in the US, that’s been known for a while. To go anywhere you have to present photo ID, have your bags x-rayed, have somebody physically inspect your shoes, electronics and medication, and pass through a metal detector, if you’re lucky…but more than likely a millimeter-wave scanner and possibly a pat-down.

    Short of flying private/charter, that’s pretty much the only option for commercial flight.

    You can sometimes save yourself the hassle and take a train or a bus (or more likely a combination of several), if you don’t mind taking forever, and trains usually costing more than flights. Or just do what any other good red-blooded American would and take your pickup truck.