LiamO 's Techdirt Comments

Latest Comments (3) comment rss

  • Trustwave Admits It Issued A Certificate To Allow Company To Run Man-In-The-Middle Attacks

    LiamO ( profile ), 08 Feb, 2012 @ 08:53pm

    I can see why companies would want to be able to man-in-the-middle outbound connections from their own corporate network. SSL/TLS can be used to tunnel... well anything really. A malware C&C channel, a way to exfiltrate corporate data etc.

    However, the correct way to implement this is the exact opposite of what Trustwave has done. An SSL proxy like Bluecoat achieves the above goal of MITM'ing corporate SSL sessions by
    1)Installing a new Trusted Root Cert on all corporate PCs
    2)Using the key for that Cert to sign a faked certificate for all outbound SSL traffic
    This way, traffic is still secure between the client and the SSL proxy (using the new certificate), and between the SSL proxy and the end website (using a normal certificate)

    As long as the private key within the SSL proxy remains secure, the system is secure (or securish... an admin from your company with access to the proxy could still sniff your SSL traffic - a good reason not to do your net banking at work)

    The important difference between an SSL proxy and the ridiculous decision by Trustwave is the failure modes of the system.

    Worst case scenarios:

    If a hacker gains access to the private key within Company A's SSL proxy, they can MITM computers that belong to Company A. Fair enough, as it was Company A's security failure that led to the key exposure in the first place.

    If a hacker gains access to the private key corresponding to the CA certificate that Trustwave issued, until somebody notices and discloses the key compromise and the certificate gets revoked, the hacker can MITM anyone, anywhere, anytime.

    See why it's not as good a solution?

  • Warner Bros. Buys Story That Was Written In The Reddit Comments; Then Tells Author To Stop Redditing

    LiamO ( profile ), 17 Oct, 2011 @ 03:51pm

    Already done in comic form

    This sounds like a very similar premise to Jonathan Hickmans excellent graphic novel, Pax Romana
    http://en.m.wikipedia.org/wiki/Pax_Romana_(comics)

  • Entrepreneurs Who Create Value vs. Entrepreneurs Who Lock Up Value

    LiamO ( profile ), 03 Feb, 2011 @ 05:56pm

    Response to: Rekrul on Feb 3rd, 2011 @ 5:00pm

    Google buying YouTube for $1.6 billion while it was still full of infringing content would argue otherwise