I've published a text version of my #37C3 lightning talk! "The browsers biggest TLS mistake" https://blog.benjojo.co.uk/post/browsers-biggest-tls-mistake
mirabilos@toot.mirbs..
replied 07 Jan 2024 16:04 +0000
in reply to: https://benjojo.co.uk/u/benjojo/h/nPY3pC4f393j6jt1r9
benjojo
replied 07 Jan 2024 17:38 +0000
in reply to: https://toot.mirbsd.org/users/mirabilos/statuses/01HKJAPJR3JBVJSH4S263VB0PV
@mirabilos I did the same with my previous CCC talk https://blog.benjojo.co.uk/post/dive-into-the-world-of-dos-viruses
mirabilos@toot.mirbs..
replied 07 Jan 2024 17:54 +0000
in reply to: https://benjojo.co.uk/u/benjojo/h/1YXrMF1fNRC8s6f17G
fanf@mendeddrum.org
replied 07 Jan 2024 20:15 +0000
in reply to: https://benjojo.co.uk/u/benjojo/h/nPY3pC4f393j6jt1r9
@benjojo nice talk, i am once more boggling at google chrome i have read somewhere that microsoft edge downloads root certs on demand, dunno if it does that for intermediate certs too…
cks@mastodon.social
replied 07 Jan 2024 21:10 +0000
in reply to: https://mendeddrum.org/users/fanf/statuses/111716500956293813
@fanf @benjojo In theory I think you can often download intermediates if you want to, because I believe many TLS certificates have an embedded 'Issuing Certificate URL'. Of course there are various issues with fetching random URLs during TLS certificate validation, so I can understand why browsers could well nope out of doing so.
benjojo
replied 08 Jan 2024 00:04 +0000
in reply to: https://mendeddrum.org/users/fanf/statuses/111716500956293813
@fanf The "downloads root certs on demand" is likely AIA, the thing I glossed over in my talk because it's a separate lightning talk of slightly cursed!
ollibaba@chaos.socia..
replied 07 Jan 2024 15:24 +0000
in reply to: https://benjojo.co.uk/u/benjojo/h/nPY3pC4f393j6jt1r9
@benjojo Yes! These missing intermediate certificates are my personal pet peeve! This is especially a problem since I usually create a new Firefox profile for each window, which then lacks many of the "usual" intermediate certificates, and therefore I get many more SSL errors. And in many cases these SSL errors do not occur for the website operators, making it really difficult to convince them that they need to fix something on their side.
sss@pleroma.dark-ale..
replied 07 Jan 2024 16:11 +0000
in reply to: https://benjojo.co.uk/u/benjojo/h/nPY3pC4f393j6jt1r9
gamingrobot@infosec...
replied 07 Jan 2024 23:51 +0000
in reply to: https://benjojo.co.uk/u/benjojo/h/nPY3pC4f393j6jt1r9
@benjojo I had setup "A bad TLS server" and only figured out it was a problem when my e-reader couldn't validate the cert.
eddyg@mastodon.socia..
replied 08 Jan 2024 05:17 +0000
in reply to: https://benjojo.co.uk/u/benjojo/h/nPY3pC4f393j6jt1r9
@benjojo Appreciate you taking the time to create a text version of your talk! What about needlessly including the Root CA in the cert bundle sent by the browser? I see it included in the “full chain” all the time, but I’m always careful to remove it, since it seems to me like any extra data sent during the initial part of a TLS connection will have a bigger impact because of TCP slow start…
LeonVQZ@infosec.town
replied 08 Jan 2024 10:03 +0000
in reply to: https://benjojo.co.uk/u/benjojo/h/nPY3pC4f393j6jt1r9