[Cryptography] Opening Discussion: Speculation on "BULLRUN"

Eugen Leitl eugen at leitl.org
Sat Sep 7 14:02:57 PDT 2013


----- Forwarded message from Phillip Hallam-Baker <hallam at gmail.com> -----

Date: Sat, 7 Sep 2013 16:20:18 -0400
From: Phillip Hallam-Baker <hallam at gmail.com>
To: Gregory Perry <Gregory.Perry at govirtual.tv>
Cc: "cryptography at metzdowd.com" <cryptography at metzdowd.com>, ianG <iang at iang.org>
Subject: Re: [Cryptography] Opening Discussion: Speculation on "BULLRUN"

On Sat, Sep 7, 2013 at 3:13 PM, Gregory Perry <Gregory.Perry at govirtual.tv>wrote:

> >If so, then the domain owner can deliver a public key with authenticity
> >using the DNS.  This strikes a deathblow to the CA industry.  This
> >threat is enough for CAs to spend a significant amount of money slowing
> >down its development [0].
> >
> >How much more obvious does it get [1] ?
>
> The PKI industry has been a sham since day one, and several root certs
> have been compromised by the proverbial "bad guys" over the years (for
> example, the "Flame" malware incident used to sign emergency Windows
> Update packages which mysteriously only affected users in Iran and the
> Middle East, or the Diginotar debacle, or the Tunisian "Ammar" MITM
> attacks etc).  This of course is assuming that the FBI doesn't already
> have access to all of the root CAs so that on domestic soil they can
> sign updates and perform silent MITM interception of SSL and
> IPSEC-encrypted traffic using transparent inline layer-2 bridging
> devices that are at every major Internet peering point and interconnect,
> because that would be crazy talk.
>

Before you make silly accusations go read the VeriSign Certificate
Practices Statement and then work out how many people it takes to gain
access to one of the roots.

The Key Ceremonies are all videotaped from start to finish and the auditors
have reviewed at least some of the ceremonies. So while it is not beyond
the realms of possibility that such a large number of people were suborned,
I think it drastically unlikely.

Add to which Jim Bizdos is not exactly known for being well disposed to the
NSA or key escrow.


Hacking CAs is a poor approach because it is a very visible attack.
Certificate Transparency is merely automating and generalizing controls
that already exist.

But we can certainly add them to S/MIME, why not.

-- 
Website: http://hallambaker.com/

_______________________________________________
The cryptography mailing list
cryptography at metzdowd.com
http://www.metzdowd.com/mailman/listinfo/cryptography


----- End forwarded message -----
-- 
Eugen* Leitl <a href="http://leitl.org">leitl</a> http://leitl.org
______________________________________________________________
ICBM: 48.07100, 11.36820 http://ativel.com http://postbiota.org
AC894EC5: 38A5 5F46 A4FF 59B8 336B  47EE F46E 3489 AC89 4EC5



More information about the cypherpunks mailing list