Privacy-Preserving & Incrementally-Deployable Support for Certificate Transparency in Tor

Author:

Dahlberg Rasmus1,Pulls Tobias1,Ritter Tom,Syverson Paul2

Affiliation:

1. Karlstad University

2. U.S. Naval Research Laboratory

Abstract

Abstract The security of the web improved greatly throughout the last couple of years. A large majority of the web is now served encrypted as part of HTTPS, and web browsers accordingly moved from positive to negative security indicators that warn the user if a connection is insecure. A secure connection requires that the server presents a valid certificate that binds the domain name in question to a public key. A certificate used to be valid if signed by a trusted Certificate Authority (CA), but web browsers like Google Chrome and Apple’s Safari have additionally started to mandate Certificate Transparency (CT) logging to overcome the weakest-link security of the CA ecosystem. Tor and the Firefox-based Tor Browser have yet to enforce CT. In this paper, we present privacy-preserving and incrementally-deployable designs that add support for CT in Tor. Our designs go beyond the currently deployed CT enforcements that are based on blind trust: if a user that uses Tor Browser is man-in-the-middled over HTTPS, we probabilistically detect and disclose cryptographic evidence of CA and/or CT log misbehavior. The first design increment allows Tor to play a vital role in the overall goal of CT: detect mis-issued certificates and hold CAs accountable. We achieve this by randomly cross-logging a subset of certificates into other CT logs. The final increments hold misbehaving CT logs accountable, initially assuming that some logs are benign and then without any such assumption. Given that the current CT deployment lacks strong mechanisms to verify if log operators play by the rules, exposing misbehavior is important for the web in general and not just Tor. The full design turns Tor into a system for maintaining a probabilistically-verified view of the CT log ecosystem available from Tor’s consensus. Each increment leading up to it preserves privacy due to and how we use Tor.

Publisher

Walter de Gruyter GmbH

Subject

General Medicine

Reference70 articles.

1. [1] J. Aas, R. Barnes, B. Case, Z. Durumeric, P. Eckersley, A. Flores-López, J. A. Halderman, J. Hoffman-Andrews, J. Kasten, E. Rescorla, S. D. Schoen, and B. Warren. Let’s Encrypt: An automated certificate authority to encrypt the entire web. In CCS, 2019.10.1145/3319535.3363192

2. [2] M. Alicherry and A. D. Keromytis. DoubleCheck: Multi-path verification against man-in-the-middle attacks. In ISCC, 2009.10.1109/ISCC.2009.5202224

3. [3] Apple Inc. Apple’s certificate transparency log program, January 2019. https://support.apple.com/en-om/HT209255, accessed 2020-12-15.

4. [4] Bugzilla. Implement certificate transparency support (RFC 6962), 2020. https://bugzilla.mozilla.org/show_bug.cgi?id=1281469, accessed 2020-12-15.

5. [5] Catalin Cimpanu. Exploit vendor drops Tor Browser zero-day on Twitter, 2018. https://web.archive.org/web/20200529194530/https://www.zdnet.com/article/exploit-vendor-drops-tor-browser-zero-day-on-twitter/, accessed 2020-12-15.

Cited by 5 articles. 订阅此论文施引文献 订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献

1. Tor network anonymity evaluation based on node anonymity;Cybersecurity;2023-11-08

2. Sauteed Onions;Proceedings of the 21st Workshop on Privacy in the Electronic Society;2022-11-07

3. Certificate Transparency With Enhanced Privacy;IEEE Transactions on Dependable and Secure Computing;2022

4. Attacks on Onion Discovery and Remedies via Self-Authenticating Traditional Addresses;Proceedings of the 20th Workshop on Workshop on Privacy in the Electronic Society;2021-11-15

5. Principles of Remote Sattestation;Protocols, Strands, and Logic;2021

同舟云学术

1.学者识别学者识别

2.学术分析学术分析

3.人才评估人才评估

"同舟云学术"是以全球学者为主线,采集、加工和组织学术论文而形成的新型学术文献查询和分析系统,可以对全球学者进行文献检索和人才价值评估。用户可以通过关注某些学科领域的顶尖人物而持续追踪该领域的学科进展和研究前沿。经过近期的数据扩容,当前同舟云学术共收录了国内外主流学术期刊6万余种,收集的期刊论文及会议论文总量共计约1.5亿篇,并以每天添加12000余篇中外论文的速度递增。我们也可以为用户提供个性化、定制化的学者数据。欢迎来电咨询!咨询电话:010-8811{复制后删除}0370

www.globalauthorid.com

TOP

Copyright © 2019-2024 北京同舟云网络信息技术有限公司
京公网安备11010802033243号  京ICP备18003416号-3