Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Sign up for free
Menu
Search
Features
All features
Private URLs
Password Protection
Custom URLS
Scheduled publishing
Remove Branding
Restrict embedding
Deck Collections
Notes
Features
All features
Private URLs
Password Protection
Custom URLS
Scheduled publishing
Remove Branding
Restrict embedding
Deck Collections
Notes
Explore
Featured decks
Featured speakers
Programming
Technology
Storyboards
Explore
Featured decks
Featured speakers
Programming
Technology
Storyboards
Pricing
Search
Sign in
Sign up for free
SSL, CAs and keeping your stuff safe
Search
Armin Ronacher
May 10, 2014
Programming
1.1k
7
Share
Embed
Copy iframe code
Copy JS code
Copy link
Start on current slide
SSL, CAs and keeping your stuff safe
A capitalistic and system conformant talk about encryption.
Armin Ronacher
May 10, 2014
More Decks by Armin Ronacher
See All by Armin Ronacher
Reflections on building cloud and local hybrid machine entities
mitsuhiko
1
190
Agentic Coding: The Future of Software Development with Agents
mitsuhiko
0
930
Do Dumb Things
mitsuhiko
0
1k
No Assumptions
mitsuhiko
0
440
The Complexity Genie
mitsuhiko
0
350
The Catch in Rye: Seeding Change and Lessons Learned
mitsuhiko
0
460
Runtime Objects in Rust
mitsuhiko
0
450
Rust at Sentry
mitsuhiko
0
620
Overcoming Variable Payloads to Optimize for Performance
mitsuhiko
0
320
Other Decks in Programming
See All in Programming
一人だけ、Kiroが静止する日
hideg
0
110
数年滞っていたダークモード対応をおよそ2週間で完了させる
chigichan24
0
720
個人開発基盤をまるごとCloudflareに引っ越して爆速で総合的体験を向上させた話
tinykitten
0
190
大喜利で理解するLLM as a Judge / Understanding LLM-as-a-Judge through Ogiri
rockname
0
120
Vibes Containers 〜AIで変わるコンテナ設計と運用〜
tkikuc
3
550
標準パッケージに uuid が追加された 背景から見る Go らしい意思決定 / go_127_uuid_decision
convto
5
7.3k
kubernetes コンポーネント開発入門 / 新卒N年目の勉強会&交流会!〜〇〇への誘い〜 #n_study
mazrean
0
240
setup-vp GitLab対応の裏側
naokihaba
0
100
更なる可用性を求めて、5年間運用したKotlinのアプリケーションをGoでリプレイスする話
ken_tunc
0
270
MVNOの申込からeSIM開通までをiOSアプリでつなぐ- 本人確認・MNP・通信事業者基盤をまたぐ実装
satotakeshi
0
420
Everything will be SERVERLESS — 信じて運用した10年の経験値 / Everything Will be Serverless — Lessons Learned from 10 Years of Operational Experience
seike460
PRO
1
110
Intent as Code
shoppingjaws
6
1k
Featured
See All Featured
The Invisible Side of Design
smashingmag
301
52k
Building the Perfect Custom Keyboard
takai
2
870
Rebuilding a faster, lazier Slack
samanthasiow
85
9.6k
The Curious Case for Waylosing
cassininazir
1
510
What Being in a Rock Band Can Teach Us About Real World SEO
427marketing
0
1.1k
Effective software design: The role of men in debugging patriarchy in IT @ Voxxed Days AMS
baasie
1
530
Marketing Yourself as an Engineer | Alaka | Gurzu
gurzu
0
300
State of Search Keynote: SEO is Dead Long Live SEO
ryanjones
0
280
Building AI with AI
inesmontani
PRO
1
1.2k
Bioeconomy Workshop: Dr. Julius Ecuru, Opportunities for a Bioeconomy in West Africa
akademiya2063
PRO
1
360
The MySQL Ecosystem @ GitHub 2015
samlambert
251
13k
Lightning talk: Run Django tests with GitHub Actions
sabderemane
0
260
Transcript
SSL, CAs and keeping your stuff safe BQSFTFOUBUJPOCZBSNJOSPOBDIFSGPSQZHSVOO http://lucumr.pocoo.org/ —
@mitsuhiko
SSL, CAs and keeping your stuff safe BQSFTFOUBUJPOCZBSNJOSPOBDIFSGPSQZHSVOO http://lucumr.pocoo.org/ —
@mitsuhiko a capitalistic and system conformant talk about encryption
Armin Ronacher Independent Contractor for Splash Damage / Fireteam Doing
Online Infrastructure for Computer Games
… The Problem with Programmers ~ Epilogue ~
Programmers think everything is a technical problem
Fraud ~ Chapter 1 ~
XXXX-XXXX-XXXX-1234 What is the worst that can happen?
What makes Credit Card Numbers “secure”?
theft ere will always be criminals
prevented But what damage can they do?
Bitcoin A Credit Card Strong Encryption Potentially No Encryption 256
bit private key 16 digit number + checksum decentralized centralized √ x
But I'd rather lose my credit card …
Never
LOL
We Accept Stolen Creditcards
e Protocol e Process is insecure is secure
If the aud percentage is smaller than the transaction fees
we're all good.
It's too easy to forget the bigger picture
of Lock Symbols and Encryption ~ Chapter 2 ~
the lock symbol is a lie
the lock stands for secure
but so is encryption 8 7
such security
such buzzwords CRIME BEAST Heartbleed BREACH PFS
users need to understand how to keep good om bad
lock symbols / good om bad encryption. = -
but even developers are not sure yet …
remember why you encrypt (NSA
Why do we Encrypt Traffic? ~ Chapter 3 ~
None
public WiFi the unencrypted browser session kilLed
? Who is the Attacker?
om secret agents to idiots
om targeted to untargeted
om low to high probability
What You Need for Encryption ~ Chapter 4 ~
passive vs active eavesdropping encryption authentication
$ ssh pocoo.org The authenticity of host 'pocoo.org (148.251.50.164)' can't
be established. RSA key fingerprint is 14:23:83:02:45:f9:9c:d0:eb:39:c7:14:42:f5:9f:9c. Are you sure you want to continue connecting (yes/no)?
your user does not check ngerprints (your
e Certificate Authorities thus:
CAs are worthless for securing APIs let it be known
that
Protecting APIs and Services ~ Chapter 5 ~ (non
The Only Rule to Follow
run your own CA issue certi cates for 24 hours
trust your own CA only screw re ocations
You trust your own CA by distributing the certi cate
to everybody.
If your root gets compromised, distribute new root certi cates.
If an individual key gets compromised, in less than 24
hours everything is ne.
from requests import get resp = get('https://api.yourserver.com/', verify='your/certificate.bundle')
“But my awesome AntiVirus says your certi cate is not
trusted.” — Windows User
Certificate Authorities Again ~ Chapter 6 ~
Hardly news: CAs are Broken
But why are the broken?
I Trust “TÜRKTRUST Elektronik Serti ka Hizmet Sağlayıcısı” to ouch
for the identity of any domain on the planet. Trusting a CA:
trusting half the world: one shitty employee in one shitty
CA is enough to break your security.
I Trust “Comodo” to ouch for the identity of “Foo
Owner” foo.com. I only trust “Foo Owner” to ouch for the identity of api.foo.com What we actually want:
if you have seen google.com being from Verisign and all
the sudden google.com becomes a StartSSL certificate you know something might be wrong.
Soon: Certificate Pinning?
Frack OpenSSL and Question “Best Practices” ~ Chapter 7 ~
Self-Signed Certificates are not bad. Just in browsers.
Never. Ever. Look at OpenSSL's Source.
OpenSSL's "patches" are even worse: Apple's OpenSSL always trusts system
store :-/
Requests by default trusts it's own bundle :-/ (And does
not even properly document how to use custom ones)
With Heartbleed SSL was less secure than no SSL :-/
Growing SSL ~ Chapter 8 ~
Credit Cards were made for thousands of people Certificate Authorities
were made for hundreds of sites
OpenSSL was probably improperly audited
See “OpenSSL Valhalla Rampage” :-( “i give up. reuse problem
is unixable. dlg says puppet crashes” — tedu
Plan for Failure ~ Chapter 9 ~
what
what happens to your user if he gets hacked? (food
for thought: keyloggers are still a thing)
what happens to your data
what happens to your company
encryption is hardened security it must not be your only
defense
? Feel Free To Ask Questions Talk slides will be
online on lucumr.pocoo.org/talks You can find me on Twitter: @mitsuhiko And gittip: gittip.com/mitsuhiko Or hire me:
[email protected]