www.enisa.europa.eu
Operation Black tulip: Certificate authorities loose authority
24th Annual FIRST Conference 19 June 2012, Malta
- Dr. Marnix Dekker, CISA
Security expert Information security officer ENISA
Operation Black tulip: Certificate authorities loose authority 24th - - PowerPoint PPT Presentation
Operation Black tulip: Certificate authorities loose authority 24th Annual FIRST Conference 19 June 2012, Malta Dr. Marnix Dekker, CISA Security expert Information security officer ENISA www.enisa.europa.eu About ENISA o The European
www.enisa.europa.eu
24th Annual FIRST Conference 19 June 2012, Malta
Security expert Information security officer ENISA
www.enisa.europa.eu
is on prevention and preparedness.
2
www.enisa.europa.eu
3
www.enisa.europa.eu 4
www.enisa.europa.eu
5
www.enisa.europa.eu
authorising users
great possibilities of public key cryptography
(SSL + CA’s in the browser + OCSP) is flawed.
6
www.enisa.europa.eu 7
… and this has been argued in many articles by well known experts.
www.enisa.europa.eu
appear sophisticated, mature, and mass-produced… an active vendor community”
tiny, obscure businesses to various national governments”
future-of-authenticity : Repeated hacks of CAs, and you don’t even need to hack.
8
www.enisa.europa.eu 9
And then…
www.enisa.europa.eu 10
For several weeks in August 2011
www.enisa.europa.eu 11
For several weeks in September 2011
www.enisa.europa.eu
12
Security breach at Diginotar Privacy breach in Iran Outage in the Netherlands
July 2011 August 2011 September 2011
www.enisa.europa.eu 13
Let’s look at the impact, starting small first…
www.enisa.europa.eu 14
www.enisa.europa.eu 15
www.enisa.europa.eu 16
Mikko Hyppönen: “It is plausible that people died.”
www.enisa.europa.eu 17
Critical information infrastructure: Those interconnected information systems and networks, the disruption or destruction of which would have a serious impact on the health, safety, security, or economic well-being of citizens, or on the effective functioning of government or the economy. (So the CA’s in your country are critical information infrastructure)
www.enisa.europa.eu 18
www.enisa.europa.eu
details of the implementation)
compliant with security standards
19
www.enisa.europa.eu 20
Is new regulation enough?
www.enisa.europa.eu 21
(meaning: attacker needs to succeed at compromising 1 of 600 to allow attacks on any website!)
www.enisa.europa.eu 22
www.enisa.europa.eu 23
Aart Jochem (NCSC.nl) @ FIRSTCON 2012: “The Diginotar crisis is over, but the PKI crisis is still ongoing.”
www.enisa.europa.eu 24
Key issues to address…
www.enisa.europa.eu
25
www.enisa.europa.eu
seat-belt that snaps when you crash. “
available OCSP responders at CA’s.
page loading.
visited which websites.
26
www.enisa.europa.eu
bars, locks, warnings – do they help?
showed the wrong certificate for one hour.
27
www.enisa.europa.eu
everyone else.
small ones, with a tough business model
certificate business in the first half of 2011. ”
attack pressure facing billion dollar companies?
the larger websites for conveying trust?
28
www.enisa.europa.eu
29
www.enisa.europa.eu
Contact
CIIP and Resilience, ENISA marnix.dekker@enisa.europa.eu www.enisa.europa.eu http://twitter.com/marnixdekker
30