If you, like me, have worked for some corporation, or even smaller company with an Intranet, then you'd recognize this kind of screenshots:It's a long standing security issue and the one I just read an article about here
For people without due understanding of certificates and why they are used, this is a non-issue - they just click "Continue" or something to that effect - and go on.
But the devil is in the details, as we know.
I think it's about time we stopped allowing that.
Besides presenting a usability issue, namely a "nag" dialog, it also de-voids one of two purposes of certificates - it does not verify the server's authenticity, allowing for so called "man-in-the-middle" attack.
The second, remaining, purpose is encryption against eavesdropping, but this one will also be crippled if you're talking to "the wrong" server after clicking "Continue" on invalid certificate.
Simply because the eavesdropper will be the non-authenticated (fake, malicious) server with similarly incorrect certificate, to which you'd blindly accept connection.
Such practice had been "convenient to user", who needed a way to access things, and "merciful to developer" who did not want to spend money on SSL certificates from established Certificate Authorities.
Well, there's been epoch with no condoms, and people suffered greatly while not realizing there's an exit.
As more and more electronic fraud and hacking dilutes quality of online life, there's more and more need to establish better standard practices.
Now web looks like only richer folks can buy needed protection. The rest of us have to "blindly click extra".
Time to revisit what stops us from helping every website?
I would suggest to "close the cap" by disabling access from all browsers to invalid certificates.
The only exception left would be VALID self-signed certificates, but they should be separately indicated in browsers by a special icon (not the padlock as with CA-signed certificates). Such exception leaves out one vector of attack - DNS.
And for future development, there is a need to secure DNS, too.
I think there can be one solution to both problems.
An option to get certificate when registering your domain name!
(Directly from the registrar.)
Think of this - we trust DNS, should not this trust be augmented by certification?
Unfortunately, this would mean serious increase in business for registrars and decrease for CAs.
Well, good does not come without changing.
Besides, I think they are in the right position to lobby this as a new web standard.
For registrars, that would be an additional competition vector.
No comments:
Post a Comment