• Some users have recently had their accounts hijacked. It seems that the now defunct EVGA forums might have compromised your password there and seems many are using the same PW here. We would suggest you UPDATE YOUR PASSWORD and TURN ON 2FA for your account here to further secure it. None of the compromised accounts had 2FA turned on.
    Once you have enabled 2FA, your account will be updated soon to show a badge, letting other members know that you use 2FA to protect your account. This should be beneficial for everyone that uses FSFT.

Web Users Ignoring Security Certificate Warnings

HardOCP News

[H] News
Joined
Dec 31, 1969
Messages
0
Carnegie Mellon researchers say that digital certificate warnings in web browsers are not an effective security measure. An online study found that most people just ignore warnings about expired SSL certificates. The study also found that the more tech savvy the user, the more likely they would ignore the warnings.

The researchers, who plan to present their findings on August 14 at the Usenix Security Symposium in Montreal, found over the course of two experiments that certificate warnings were ineffectual. The warnings appear when a browser detects a problem with a Web site's certificate and arrive as a pop-up with a message such as: "There is a problem with this Web site's security certificate."
 
thats because 99% of the time they only block legit programs not viruses, spyware etc...

its a pain in the ass microsoft. we end up having to disable warn about site certs (advance tab in ie) ... to get citrix to run on some machines.
 
Tech savvy users also rarely get viruses. I'd presume primarily because we don't haphazardly click links for free shit, especially porn.
 
thats because 99% of the time they only block legit programs not viruses, spyware etc...

its a pain in the ass microsoft. we end up having to disable warn about site certs (advance tab in ie) ... to get citrix to run on some machines.

Spot on with my experience. Further, customers- even huge ones- don't update their stuff right away when things change. When IE7 came out, oy vey.
 
Yep - certificates are worthless, no doubt. Warnings pop up with too many legit sites for them to mean anything.
 
Yep - certificates are worthless, no doubt. Warnings pop up with too many legit sites for them to mean anything.

Only "homemade" certificates are worthless. I only accept certificates if I trust the server (my company's client's sharepoint server for example) or if the certificate is generated by Thawte or GeoTrust. They don't just give away certificates to buyers. They do background checks on you.
 
They don't just give away certificates to buyers. They do background checks on you.

That's the issue. Screw paying someone to give you a POS cert to "verify" your identity. We paid for the OS, we paid for the networking software, we paid for the licenses, we pay, we pay, we pay some more. I'm not on board with paying someone just becuase it happens to be "trusted" with a damn browser. Use our SSL or piss off.
 
That's the issue. Screw paying someone to give you a POS cert to "verify" your identity. We paid for the OS, we paid for the networking software, we paid for the licenses, we pay, we pay, we pay some more. I'm not on board with paying someone just becuase it happens to be "trusted" with a damn browser. Use our SSL or piss off.

Normally I'd agree with you, but businesses such as the ones I work for don't have the time or desire to worry about sites we cannot trust because Thawte hands out certs like candy (pun intended). I'm sure there are SSL vendors that gives them away, but there should be one or two that doesn't.
 
That is because the whole point of the certs is being missed. Certs are not to tell if an encrypted page is secure. The fact that it is encrypted probably means it is secure. Certs are for authenticating that who you are having the secure conversation is with who you think you are. Do I care if some forum I visit to find some info from a google search has an expired cert? No, but I would care if my band has bad cert and would not ignore that one. The problem is browsers have started classifying encryption without authentication as somehow being worse than no encryption. It should be the other way around and browsers should figure out how to treat authentication and encryption as two seperate issues.
 
whats even worse is how small the yellow warning is in ie... the average user does this:

a. ignores it because its not something they are aware of
b. think a website/download is broken (legit) since its blocked iwth a toolbar that is retarded
 
All a certificate does is tell you the person is supposedly who they say they are. Having an expired certificate, especially from a longstanding site only says the haven't reverified with Verisign again yet and forked over more cash. The certificate still works, its just expired. Even Steve Gibson of Shields Up! and Security Now forgot to update his certificate right away recently. Again, no one cares and it doesn't mean anything really.
 
thats because 99% of the time they only block legit programs not viruses, spyware etc...

its a pain in the ass microsoft. we end up having to disable warn about site certs (advance tab in ie) ... to get citrix to run on some machines.

Because you are using Citrix, I am going to assume you are referring to a business. Any business using certificates for user applications should have an internal trusted root CA to issue certificates.
 
If I get a certificate warning, I do a detailed examination of the certificate and make a judgement call as to whether it is an honest mistake (missed renewal) or truely invalid/untrusted.

And as the previous poster stated, there is no real excuse for certificate errors on internal corporate websites (other than administrator ignorance to the proper use of certificates).
 
I actually just sent my university's IT director an email about this very issue over the weekend. In our case, the problem is that mail.xxx.edu and webmail.xxx.edu route to the same page on the same server, but the server can only issue one cert- for us, it's the www address. Consequently, anyone accessing mail.xxx.edu gets a certificate error, which they almost universally ignore. Going to webmail.xxx.edu instead is clean.
 
I actually just sent my university's IT director an email about this very issue over the weekend. In our case, the problem is that mail.xxx.edu and webmail.xxx.edu route to the same page on the same server, but the server can only issue one cert- for us, it's the www address. Consequently, anyone accessing mail.xxx.edu gets a certificate error, which they almost universally ignore. Going to webmail.xxx.edu instead is clean.
"The www address" should have read "the webmail address." Sorry.
 
I've told a few shops that their certificates have expired, they didnt seem to realise either.
Always look for anything fishy.

My bank account was taken for a ride a few years ago and it was incredible hassle with bank charges and all sorts of bother.
It was satisfactorily resolved by my local bank who took it upon themselves to credit me and drop the charges while the Fraud guys got their act together!
I think it was an online shop I bought a snooker table from, the owner was as dodgy as hell and refused to take back a faulty table.
Can do without that again.
 
I actually just sent my university's IT director an email about this very issue over the weekend. In our case, the problem is that mail.xxx.edu and webmail.xxx.edu route to the same page on the same server, but the server can only issue one cert- for us, it's the www address. Consequently, anyone accessing mail.xxx.edu gets a certificate error, which they almost universally ignore. Going to webmail.xxx.edu instead is clean.

If you have to buy a cert to appease your customers (cause that's all it's good for), then get a multi-domain (UCC) cert.
 
The ignorance abound in this thread is amazing.

Amen...oy I have no idea where to start.

I think some of you need to take some time and check out some of the papers/presentations going on this week at Defcon and Blackhat where there is plenty of discussion about SSL.

The "background" checks I saw referenced earlier go only as far as to verify you own the domain. If you're referring to EV SSL, I challenge you to produce docs on how a given CA does their "validation." I doubt you'll find anything beyond marketing babble. And if you've ever purchased an EV SSL or two, you'll realize it's worthless and adds nothing.

For anyone who clicks through SSL warnings or doesn't understand what SSL does, I have a hotspot I want you to visit where I can MITM you all night...no really, it's ok, it's free.
 
All a certificate does is tell you the person is supposedly who they say they are. Having an expired certificate, especially from a longstanding site only says the haven't reverified with Verisign again yet and forked over more cash. The certificate still works, its just expired. Even Steve Gibson of Shields Up! and Security Now forgot to update his certificate right away recently. Again, no one cares and it doesn't mean anything really.

Agreed. Although, as Mr. Gibson also has stated, if it's a fairly public site (like Amazon or something) or a site you visit or buy from frequently, check the expiration date, I'm sure they are scrambling to make sure their renewal hasn't lapsed, in which case its probably not a problem. If it's a site you're not sure of, don't visit often enough or are trying to buy something for the first time and not sure, check how long the cert has expired, the longer it's expired, the greater chance that maybe the domain no longer is being certified. Then you probably should worry.

Philip
 
Yep - certificates are worthless, no doubt. Warnings pop up with too many legit sites for them to mean anything.

Certificates are a *MAJOR* reason that SSL even works. Without certs, man in the middle attacks would basically be unstoppable. Calling them worthless just highlights your own ignorance. At least be bothered to figure out what certs even DO before commenting on them.

The real problem is that browsers don't know how to distinguish between a site that just wants encryption and one that actually wants SSL. Many sites just want basic encryption to keep out the random passerby, truly secure sites like online banking actually need valid certificates or the system breaks.
 
Certificates are extremely useful to remove the possibility of eavesdropping and stumbling upon a phishing site.

The issue is that companies are being lazy with renewal or are doing homemade certificates, which are pointless. You need a certificate from a certificate authority that is actually trusted by everyone. You need to renew when necessary.
 
Ok... expired certificate only means somebody failed to renew it, eg. pay some worthless (read verisign) company for a freaking nothing. It is still a unique certificate that was issued for a given server... So as far as the main problem listed in the first post goes.... this is non issue.
 
its a pain in the ass microsoft. we end up having to disable warn about site certs (advance tab in ie) ... to get citrix to run on some machines.
That's not Microsoft's fault.
It's yours for running a non-trusted certificate.


whats even worse is how small the yellow warning is in ie... the average user does this:

a. ignores it because its not something they are aware of
b. think a website/download is broken (legit) since its blocked iwth a toolbar that is retarded
You must not be using IE7 or IE8, because they make it abundantly obvious when a certificate is invalid.


The "background" checks I saw referenced earlier go only as far as to verify you own the domain. If you're referring to EV SSL, I challenge you to produce docs on how a given CA does their "validation." I doubt you'll find anything beyond marketing babble. And if you've ever purchased an EV SSL or two, you'll realize it's worthless and adds nothing.
QFT.
Thawte isn't better than Godaddy. If you get your basic SSL certificate (the bottom-tier EV), all it does is verify you own the domain. That's it. Godaddy does the same thing as Thawte.

EV SSL aren't totally useless. They verify you own the domain at least. About the only purpose it serves is to get rid of the warnings. Which if that's all you care about, it works.
Cost isn't a factor. I think I spent like $90 on a 5-site EV SSL certificate... Which to install one of those on each server that people connect to: well worth it.
Well worth it from having clients trying to connect and getting the SSL warnings too.
 
QFT.
Thawte isn't better than Godaddy. If you get your basic SSL certificate (the bottom-tier EV), all it does is verify you own the domain. That's it. Godaddy does the same thing as Thawte.

EV SSL aren't totally useless. They verify you own the domain at least. About the only purpose it serves is to get rid of the warnings. Which if that's all you care about, it works.
Cost isn't a factor. I think I spent like $90 on a 5-site EV SSL certificate... Which to install one of those on each server that people connect to: well worth it.
Well worth it from having clients trying to connect and getting the SSL warnings too.

It entirely depends on what level certificate you buy. Some of their certs have strict purchase policies, and some are easier to buy with a simple background check as LonerVamp mentioned.
 
Making such a comment without enlightening others to reduce or eliminate ignorance isn't much better, no?

Touché.

I didn't want to take the time to respond to each post, so I'll sum it up.

The problem starts with corporations who do not properly deploy their internal certificate authority. The root and/or intermediate certificates for their corporation are not installed on all client machines thus when users connect to a server/site that is using a cert deployed from said corporate CA the users receive a warning that the cert is not trusted. (whew)

This conditions users to click past or accept the warnings without even reading them.

Pop up blockers have absolutely nothing to do with certificate warnings.

Without certificates would you would not be able to establish an encrypted session to a webserver. Certificates are not there merely to establish the identity of the site to which a person is connecting; they are responsible for SSL/HTTPS.

SSL certificates are not issued to a specific server or IP address. They are issued to a specific domain name or common name as it is referred. The certificate can be installed on any server you like, but unless that server resolves in DNS to the name or names that are within the cert users will receive a warning that the names don't match.

There are multiple certificate authorities to choose from when purchasing a cert. Each vendor has different prices and varying degrees of background checks. If the certs from each vendor function exactly the same way, then why can company X charge so much more for the same thing than company Y?

It all comes down to brand recognition and compatibility. Some vendors have been around much longer than others so their root certificates are installed all over the place. Names like VeriSign are widely known, even by the less tech savvy users and they get away with charging a premium price.

With that being said, certificates are necessary in today's environment.

1.) They allow a secure encrypted channel to a website.
2.) They provide validation that you are connecting to who you think you are.

Point number 2 can be argued, but in a perfect world, that's the way it works. There is some degree of background checking involved to be sure that only authorized individuals are able to purchase certificates for domains they own. Don't believe me? Try and purchase an SSL certificate for www.amazon.com and let me know how successful you are.

With that being said, that doesn't mean that you should blindly trust any website that is using an SSL certificate. Use common sense. Reputable companies/corporations will not let their certs expire.
 
As an Amazon Associate, HardForum may earn from qualifying purchases.
Reputable companies/corporations will not let their certs expire.

Overall, great post. I did have an issue with this blanket statement though. Sometimes ever good companies just forget or you have two different people think the other did the renewal (this happens a lot at smaller companies) and their certificate will lapse for a day or two. Not that it should happen, but mistakes do get made. If a certificate is expired by a few days on a site I've visited for years, I'll usually send them an email if they have a contact as a opps reminder, but I won't freak out.
 
darkpaw, k1DBLITZ, LonerVamp, TechnieSooner, kllrnohj (and others):

Thanks for taking the time to explain. I take cert warnings seriously but never appreciated the details.

Of course, I'm just as likely to avoid a site if I see a spelling mistake. :)
 
Certificates are a *MAJOR* reason that SSL even works. Without certs, man in the middle attacks would basically be unstoppable. Calling them worthless just highlights your own ignorance. At least be bothered to figure out what certs even DO before commenting on them.

The real problem is that browsers don't know how to distinguish between a site that just wants encryption and one that actually wants SSL. Many sites just want basic encryption to keep out the random passerby, truly secure sites like online banking actually need valid certificates or the system breaks.


sadly, you can still trick SSL with a MITM (Man In the Middle) attack. people do not look at the details of the certificate, they normally see the box and click "accept this" and the middle machine can still pass and read any traffic from that machine to machine.

SSL is not bulletproof, but like others said, its critical for passing passwords, bank account information, etc ... because nobody believes in ethics.
 
its a pain in the ass microsoft. we end up having to disable warn about site certs (advance tab in ie) ... to get citrix to run on some machines.

This entire thread is filled with incorrect statements, but this one in particular stuck in my head.

If you have to disable certificate warnings to make anything run, it's because your PKI sucks, and whoever set it up and/or maintains it is an idiot. A good PKI is not hard to manage, and should never require you to do something as bad as disable warnings.
 
Just to clarify, an EV SSL (Extended Validation/Verification) is a higher level cert you can buy.

But "higher" level is really a misnomer and can be easily gamed. Make yourself into an LLC, pose as a few "execs" on the phone and you're fine. After that, they give you certs as long as you own the domains. And we all know you can buy any domain you want as long as you pay...

I can gladly give more details, but be prepared to be overwhelmed if you're not a security geek/tech geekc. The straight shot is: don't use untrusted networks for browsing and always be paranoid about SSL trust errors or name mismatch errors (expired certs are less risky).

Sadly, while these are valid warning signs that you're being eavesdropped upon, they are also extremely common with less-engaged administrators. And we all know if general people want to get to a site, they will get there whether they click through an error (or these days a fully rendered error page! stupid browsers...) or not. And that habit spreads indifference.

You can probably find Youtube videos of hotspot SSL MITM or hotspot sniffing and the like.
 
k1DBLITZ, thanks for taking the time. Your explanation was great; I hope many were enlightened by it.
 
Back
Top