Why browsers differ on Web sites' safety

 

Summary

The Comodo security breach shows that each major browser maker ships a different list of master keys to Web authentication and that each creates its list in a different way.

Events

Echelon 2012
June 11 and 12, 2012

University Cultural Centre, National University of Singapore

Startup Asia Jakarta 2012
June 7 and 8, 2012

12th Floor, Annex Building, Wisma Nusantara Complex, Jl. M.H. Thamrin No. 59 Jakarta 10350, Indonesia

MMA Forum Singapore
April 23-25, 2012

Grand Hyatt Singapore

For all the tens of billions of dollars a year spent on Internet security a year, on everything from antivirus software to intrusion prevention, there's one component that's vital but remains obscure: which Web sites browsers decide to trust.

Each of the major browser makers has compiled a different list of who possesses the master keys to Web authentication--namely, who can be trusted to issue the secure digital certificates to create encrypted channels--and each has different procedures for approval. A closed lock icon typically appears in a browser and an "https://" connection is displayed when a Web site is deemed legitimate.

The flaws in this system were thrown into sharp relief by last week's revelation that a hacker traced to Iran obtained fake digital certificates for Google, Yahoo, Microsoft, and other companies. Comodo, a Jersey City, N.J.-based firm, said it revoked the nine certificates as soon as it discovered the breach in a business partner's systems.
 

Today's system gives browser makers tremendous responsibility. Any list of so-called certificate authorities they include will be trusted by billions of Web browsers around the world, unless users take the time to change the settings. The surprise is, perhaps, that the lists of who's trusted aren't the same.

"Microsoft appears to generally trust a much larger set of certificate authorities than Mozilla does," says Peter Eckersley, senior staff technologist at the Electronic Frontier Foundation. "That may be because Microsoft's criteria are easier to meet in practice, or because certificate authorities prioritize getting onto Microsoft's list first."

Mozilla ships Firefox with a list of about 150 trusted certificate authorities. The list included with Microsoft Windows, used by Internet Explorer, totals 321 as of last week.

Opera includes only 37. Apple's OS X operating system, which Safari relies on, trusts 79 certificate authorities. Google says Chrome uses the Windows or OS X lists; Google Checkout trusts 168.

It's difficult to compare those numbers directly, though, because some certificate authorities are counted multiple times. VeriSign appears 55 times in Microsoft's list based on different types of products offered but only once in Opera's, for instance.

Microsoft explicitly trusts more government-operated certificate authorities than any other browser maker. The list includes: Brazil, Hong Kong, India, Japan, Latvia, Lithuania, Serbia, Slovenia, the United States, Tunisia, Turkey, Uruguay, and Venezuela.

Another complicating factor is that some browsers download updated lists of "root" certificate authorities as needed.

Opera's default "list starts out with a limited number of frequently used certificates," says Yngve Pettersen, a senior developer at Opera Software in Oslo, Norway. "The remainder are downloaded as needed from certs.opera.com when the user actually visits a site issued from a root...We pre-ship some roots and also some intermediates, while others are downloaded dynamically."

What makes the list of trusted certificate authorities crucial is that each possesses the master keys to Web authentication. Companies like Etisalat, a wireless carrier in the United Arab Emirates that implanted spyware on customers' BlackBerry devices, can generate certificates that can be used to impersonate any secure Web site on the Internet. So do more than 100 German universities, the U.S. Department of Homeland Security, and random organizations like the Gemini Observatory, which operates a pair of 8.1-meter-diameter telescopes in Hawaii and Chile.

A fraudulent certificate would allow a network provider (or a government) to use what's known as a man-in-the-middle attack to impersonate the legitimate sites and grab passwords, read e-mail messages, and monitor any other activities on those Web sites, even if browsers show that the connections were securely protected with SSL encryption. And in the last few years, plenty of other techniques have emerged to trick computers into visiting fake Web sites even without control of the network.

Microsoft says it included the Tunisian government as a trusted certificate authority after it went through the normal application process.

"Microsoft requires that certificate authorities applying to the program provide standardized information," says Bruce Cowper, Microsoft's group manager for trustworthy computing. Tunisia applied in 2006, he said, and its certificate was distributed in February 2007. Venezuela applied in September 2010, and was approved a month later.

Cowper declined to provide information about how many companies, organizations, or governments have failed to pass muster, saying "Microsoft does not share specific information about denied applications, but we do reject applications from certificate authorities who don't meet our criteria (or) fall into one of the named exclusions from the program." Microsoft's specifications say that any certificate authority that fails an audit, for instance, will be given the boot.

If a certificate authority "isn't in our list it is either because they have not asked to be included, or have not yet been approved," says Opera's Pettersen. "So far, I don't think we have refused any certificate authorities that have applied." Neither Tunisia nor Venezuela have sent Opera an application to be included, he said.

Neither Apple nor Comodo responded to requests for comment.

While both Microsoft and Opera make their criteria public, Mozilla goes further and even makes the list of pending applications public. Those include a certificate authority operated government of the Valencia region of Spain and Deutscher Sparkassen Verlag GmbH, the world's largest smartcard provider.

As a result of the Comodo breach (Comodo is currently trusted by all the major browsers), there's been talk among Mozilla developers of imposing what amounts to the Internet death penalty: revoking the company's certificate authority, at least until a security audit is performed, from the default Firefox configuration.

Lending ammunition to critics is that this is not the first time that Comodo has experienced a serious security breach. In 2008, a reseller issued an improperly acquired certificate for Mozilla.org.

And Comodo's chief technology officer, Robin Alden, wrote in February 2010 that, before issuing a certificate, "Comodo performs an automated check of domain control by sending (and confirming receipt of) an email to an address which is either on the domain to be validated or is explicitly mentioned in the Whois entry."

That apparently wasn't done when a Comodo business partner issued those fraudulent certificates earlier this month. Comodo declined to answer questions that ZDNet Asia's sister site CNET posed last week, including the identity of its reseller, what current audits were performed, and how much authority it delegates to partners.

Elinor Mills contributed to this report

Talkback

Add your opinion

In order to post a comment, you need to be registered. (Sign In or register below)

Post your comment

ZDNet Asia Live

China solar cell makers seek Taiwan partnershipshttp://bit.ly/JErUGz via @zdnetasia #solar #energy #china

Malaysia organizations don't realize severity of cyberattacks http://t.co/PUCv68Rd

News: Radio Costa Rica by EnjoyIT 1.0: Radio Costa Rica allows you to listen to a great var... http://t.co/BLzVT5As http://t.co/1Dhcy6ki

The key for mobile operators is identifying the applications that are popular with subscribers on their network. They can then work partn...

2 hours ago by camcullen on Experience trumps content in apps monetization

Experience trumps content in apps monetization | ZDNet http://t.co/gBXcjbGd

Experience trumps content in apps monetization - ZDNet Asia News: "What we are doing currently is not to monetiz... http://t.co/S2EZtd8m

Malaysia organizations don't realize severity of cyberattacks: "Minister Maximus Johnity Ongkili said at the Sec... http://t.co/bgVlOBvx

#security Malaysia organizations don't realize severity of cyberattacks: "Minister Maximus Johnity Ongkili said ... http://t.co/hkFb4zrI

Malaysia organizations don't realize severity of cyberattacks http://t.co/EEEmRM3j via @zdnetasia

Malaysia organizations don't realize severity of cyberattacks - ZDNet Asia News http://t.co/YpNMYgb5

Malaysia organizations don't realize severity of cyberattacks http://t.co/FFems54Q

China solar cell makers seek Taiwan partnerships http://t.co/p5Hh7kJD

Big data acquisitions pave way to fast, effective innovation http://t.co/hdiEfBsz via @zdnetasia

Integration, focused investments to propel Windows Phone: By Kevin Kwang , ZDNet Asia on May 23, 2012 (2 hours a... http://t.co/E7tsZbHJ

Integration, focused investments to propel Windows Phone http://t.co/u9TqjQ8C

ZDNet Asia IT Salary Benchmark 2012 http://t.co/rVwYlV7H

So much as we know , MTK6575 extremely integrated frequency1GHz ARM Cortex-A9 processor, the superiority of 3G / HSPA Modem, and help the...

1 day ago by y15822137359 on 5 SaaS adoption speed bumps to avoid

I reckon your view: "CRM is strategy, not software", if a company replicating the approach uses in ERP implementation into CRM, what they...

2 days ago by wykoong on Gartner: Mobile CRM gives better ROI than social

This video will teach you about the Excel fill handle but also provide you with a workook to download... http://www.youtube.com/watch?v=...

3 days ago by TradeBrother on A quick fill handle trick for Microsoft Excel

waiting...

5 days ago by eapete on What should count in a company's market value?

Boy, you've opened a can of worms now.

Wait for the rants & raves.

5 days ago by eapete on What should count in a company's market value?

I was puzzling before this whether to replicate the success formula we executed for a financial institute, and come out with a standard s...

6 days ago by wykoong on Drop the egos, copy ideas, then innovate