paint-brush
Postmortem of the Firefox (and Tor Browser) Certificate Pinning Vulnerability Rabbit Holeby@flyryan
1,356 reads
1,356 reads

Postmortem of the Firefox (and Tor Browser) Certificate Pinning Vulnerability Rabbit Hole

by Ryan Duff9mSeptember 17th, 2016
Read on Terminal Reader
Read this story w/o Javascript
tldt arrow

Too Long; Didn't Read

The first few days of this vulnerability disclosure were a very interesting ride. It started with <a href="https://medium.com/@movrcx" data-anchor-type="2" data-user-id="23330eea5e9" data-action-value="23330eea5e9" data-action="show-user-card" data-action-type="hover" target="_blank">movrcx</a> posting <a href="https://hackernoon.com/tor-browser-exposed-anti-privacy-implantation-at-mass-scale-bd68e9eb1e95" target="_blank">his attack on Tor Browser</a> (which you should definitely read). Most people blew him off because they thought he didn’t understand how certificate pinning worked in Firefox and that his setup would inherently bypass pinning by design. The funny thing about that is that they were right (while still being very wrong). Going in, <a href="https://medium.com/@movrcx" data-anchor-type="2" data-user-id="23330eea5e9" data-action-value="23330eea5e9" data-action="show-user-card" data-action-type="hover" target="_blank">movrcx</a> didn’t have a great understanding of how certificate pinning in Firefox worked and neither did I for that matter. To add, had he done his attack on Firefox instead of Tor Browser, his result would have actually been the same even if a vulnerability didn’t exist. It’s kinda hard to blame anyone for blowing off his attack given the totality of the information available at the time. I almost did too.

People Mentioned

Mention Thumbnail

Companies Mentioned

Mention Thumbnail
Mention Thumbnail
featured image - Postmortem of the Firefox (and Tor Browser) Certificate Pinning Vulnerability Rabbit Hole
Ryan Duff HackerNoon profile picture
Ryan Duff

Ryan Duff

@flyryan

L O A D I N G
. . . comments & more!

About Author

TOPICS

THIS ARTICLE WAS FEATURED IN...

Permanent on Arweave
Read on Terminal Reader
Read this story in a terminal
 Terminal
Read this story w/o Javascript
Read this story w/o Javascript
 Lite
Arstechnica
Palemoon
Blogthinkbig
Lobste
Aryan
Blogspot