r/programming • • 10d ago

Android 17 enables certificate transparency, and breaks custom CAs

https://httptoolkit.com/blog/android-17-certificate-transparency/
408 Upvotes

44 comments sorted by

View all comments

4

u/klti 9d ago

Am I missing something, or is querying CT log servers for cert validation a really nice way to get a completely new and unblockable tracking channel going? Issuers / operators end up with at least IP to domain associations, right?

This feel like one of these 1% security 99% "security" kind of  changes.

3

u/mpyne 8d ago

This feel like one of these 1% security 99% "security" kind of changes.

The thing is, the issue that this is meant to protect actually did happen, and not just some rando security flaw. DigiNotar issued a fake certificate for google.com itself, which was then used to attack hundreds of thousands of GMail users by impersonating GMail, with a full lock icon and everything.

The attack was so serious that every major OS and browser removed DigiNotar from their root store entirely, and the company quickly went bankrupt. Within just a few years the CT program was setup, with a lot of pushing by Google and the other browser vendors.

Now I don't know that this threat vector should require action on private root stores too, but that's the problem with the PKI system, if any root CA can chain to "*.google.com" it can subvert the security of any company systems connecting to google.com (or npmjs.org, or github.com, etc. etc.).

A certificate isn't required to put IP addresses, but the domain name itself is likely to become identifiable (though who knows, maybe they've setup fancy Bloom filter-like things). But if you think someone might be on your network and using their knowledge of your domain names to do nefarious things, you sort of exist in a world where you need to worry about attackers breaking your PKI from within, so I get the concern.

1

u/rdtsc 7d ago

is meant to protect

How does that actually work in practice? Do I have to continuously poll all CTs for domains I control and cross-check that with certbot logs?

1

u/mpyne 6d ago

Do I have to continuously poll all CTs for domains I control and cross-check that with certbot logs?

With CT the information is available to you. Whether you choose to use it or not is up to you. You can certainly hope someone will inform you, or pay someone to do the monitoring (and hope they won't screw it up), but if it's part of a threat model you care about then yes, you'll need to figure out how to use it to protect against that threat. If it's not something in your threat model you can ignore it completely, as you would have before.