Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.project > #9330

Re: No port 443 (https) available at "security.debian.org"-repository

From Adam Borowski <kilobyte@angband.pl>
Newsgroups linux.debian.project
Subject Re: No port 443 (https) available at "security.debian.org"-repository
Date 2017-07-26 01:20 +0200
Message-ID <u7hhn-SP-9@gated-at.bofh.it> (permalink)
References <u7f5U-7HQ-27@gated-at.bofh.it> <u7f5U-7HQ-25@gated-at.bofh.it> <u7gv0-lh-11@gated-at.bofh.it> <u7hhn-SP-11@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


On Wed, Jul 26, 2017 at 07:01:36AM +0800, James Bromberger wrote:
> On 26/07/2017 6:20 AM, Adam Borowski wrote:
> > https provides no protection against targetted attacks by government agents. 
> > The CA cartel model consists of 400+ CAs, many of them outright controlled
> > by governments, most of the rest doing what they're told (no, warrants are
> > are a story for nice kids).  Clients in general trust _any_ CA, which means
> > you're only as secure as the worst CA.  Ie, https protects you against Joe
> > Script Kiddie but not against a capable opponent.
> 
> Except there are new-ish ways to limit the scope from 400+ CAs to just
> the one you use.
> c.f.
> /Certification Authority Authorization/ (/CAA/) /DNS/ Resource
> https://tools.ietf.org/html/rfc6844
> 
> ... if APT wishes to support this.

This one is meant to be used only by CAs.  And a rogue CA has no reason to
obey this request (especially if it _normally_ obeys it).

For users, the equivalent is TLSA, which allows both CA constraints and
specifying a fingerprint of the certificate itself.


-- 
⢀⣴⠾⠻⢶⣦⠀ What Would Jesus Do, MUD/MMORPG edition:
⣾⠁⢰⠒⠀⣿⡁ • multiplay with an admin char to benefit your mortal
⢿⡄⠘⠷⠚⠋⠀ • abuse item cloning bugs (the five fishes + two breads affair)
⠈⠳⣄⠀⠀⠀⠀ • use glitches to walk on water

Back to linux.debian.project | Previous | NextPrevious in thread | Next in thread | Find similar | Unroll thread


Thread

Re: No port 443 (https) available at "security.debian.org"-repository Chris Lamb <lamby@debian.org> - 2017-07-25 23:00 +0200
  Re: No port 443 (https) available at "security.debian.org"-repository Peter Palfrader <weasel@debian.org> - 2017-07-25 23:00 +0200
  Re: No port 443 (https) available at "security.debian.org"-repository Adam Borowski <kilobyte@angband.pl> - 2017-07-26 00:30 +0200
    Re: No port 443 (https) available at "security.debian.org"-repository Adam Borowski <kilobyte@angband.pl> - 2017-07-26 01:20 +0200
    Re: No port 443 (https) available at "security.debian.org"-repository James Bromberger <james@rcpt.to> - 2017-07-26 01:30 +0200
      Re: No port 443 (https) available at "security.debian.org"-repository Ondřej Surý <ondrej@sury.org> - 2017-08-04 14:10 +0200

csiph-web