News: 1591783206

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

An Internet of Trouble lies ahead as root certificates begin to expire en masse, warns security researcher

(2020/06/10)


Interview Expiring root certificates will cause devices like smart TVs and refrigerators to fail in the next few years, security researcher Scott Helme has warned.

Secure internet connections depend on the server presenting a valid certificate to the client, the most common problem being that the server certificate is out of date, easily fixed by the server admin.

In order to validate the certificate, though, the client must have a trusted root certificate from the issuing authority, and this, [1]says Helme , is a problem for devices that never get updated.

Typically root certificates have a long lifetime, such as 25 years, but nevertheless they do expire; and if one is embedded in a smart TV, fridge or security system, the consequence is that it will stop connecting while giving users little clue about what has gone wrong.

"This problem was perfectly demonstrated recently, on 30 May at 10:48:38 GMT to be exact," says Helme. "That exact time was then the AddTrust External CA [Certificate Authority] Root expired and brought with it the first signs of trouble that I've been expecting for some time."

The outcome was that some Roku streaming devices stopped working and had to be manually updated, an issue the company [2]described as "a global technical certificate expiration." There were also issues at payment providers Stripe and Spreedly.

"We're coming to a point in time now where there are lots of CA Root Certificates expiring in the next few years simply because it's been 20+ years since the encrypted web really started up and that's the lifetime of a Root CA certificate. This will catch some organisations off guard in a big way," says Helme.

Helme has worked with the BBC on this issue. When the BBC got a new certificate issued for a server recently, it used a CA root certificate dating from 2012. The problem, however, is that "the eight-year-old Root CA still hasn't managed to make its way onto a significant portion of 'Smart' TVs," he says.

It was fixed by adding additional intermediate certificates that chain to an older root certificate, giving those boxes a reprieve until 2028, but the clock is ticking. "The real solution, is that the client needs to be updated," says Helme. "Smart TV manufacturers might release updates for a couple of years, but we're talking a decade or more if you want to resolve this particular problem." The BBC "is now requiring manufacturers that want the iPlayer certification, going forwards, to resolve this."

Android smartphones may also have this issue since older devices tend not to receive updates as vendors prefer to work on newer and shinier models. "There is a significant portion of devices that are either lagging seriously behind on updates or simply aren't being updated," says Helme.

Apple does a better job of maintaining its iOS devices, however: "If you run a service with legacy clients you need to consider how your choice of CA can affect them."

Why bring the issue up now? "Up until now it's been a theoretical issue because we didn't have a demonstrable example," Helme tells The Reg . Now the BBC's workarounds, Roku's issues and more show that this is not the case. The issue is not limited to streaming media clients either. "If [a device] depends on certificates from a public CA for secure communications, this is a consideration," he says.

How many people will be affected?

"This is hard to quantify, especially as it will affect machines in the coming two to three years. Are manufacturers going to release an update? Then how is the consumer going to know that they need to install it? Is the TV going to prompt them? I thought I should start highlighting this now in that we do have a little bit of time. This is going to be a problem; we are not on top of this."

When will the next widely used root certificate expire? "Possibly March next year," he says. "Within the next 12 months we're going to have lot of things breaking, or hopefully a response from the industry to start fixing stuff."

One potentially significant date is 30 September 2021, when the DST Root CA X3 certificate used by many Let's Encrypt certificates [3]expires . Again, it is no use simply updating the certificate on the server; the client must have an updated root certificate for this to be effective.

The problem is hard for most people to understand, Helme says. "Even speaking to technology people, this is still an abstract problem to many of them. I don't think we should expect the average consumer to even think about this."

Some IoT devices such as security systems or lighting systems do make secure internet connections to enable remote control and reporting, but have no visual user interface, which could leave users perplexed as to why they no longer work. "From the consumer's perspective, the thing doesn't work. That's about as advanced a notification as they are going to get," Helme remarks.

Is it not the case that well-designed IoT devices update automatically? "There are definitely good examples out there, but I feel the good examples are the few and the bad examples are the many," Helme tells The Reg . "I think this issue is slowly manifesting itself, and the recent incident on 30 May was the first hard example of it happening."

It is all part of a broader issue, which is that "we generally aren't fantastic at keeping things up to date," in Helme's words. "If a device got updated even once every five years, this problem would not exist. I would be perfectly happy with a five-year update cycle for my refrigerator." ®

Sponsored: [4]Google Security Whitepaper



[1] https://scotthelme.co.uk/impending-doom-root-ca-expiring-legacy-clients/

[2] https://support.roku.com/en-gb/article/360049417393

[3] https://community.letsencrypt.org/t/how-to-get-certificate-of-certification-authority/22029/6

[4] https://go.theregister.com/tl/1956/-8471/google-security-whitepaper?td=wptl1956

hopefully a response from the industry to start fixing stuff

Flywheel

hopefully a response from the industry to start fixing stuff = BUY NEW STUFF.

Unfortunately...

start using DANE and CA if you must

john.jones.name

honestly yes many systems use a certification authority and its time to move on to a DNS based system where you can choose your CA (self signed or with a CA) it also nicely describes what legal system ( jurisdiction ) applies, .uk or .de

[1]https://tools.ietf.org/html/rfc7671

easy to deploy today with your existing certificate with usefulness for SMTP and in the future HTTPS

[1] https://tools.ietf.org/html/rfc7671

Re: start using DANE and CA if you must

Symon

Very interesting, ta for posting. If anyone wants a less abstruse read, you can try this:-

https://www.infoblox.com/dns-security-resource-center/dns-security-faq/what-is-dane/

Planned or accident

b0llchit

One could argue that this problem is purely accidental because products are pushed out in the name of consumerism. On the other hand, consumerism has the dark side of planned obsolescence. The cynic may argue that the problem of "not updated" or "non updateable" gadgets is a long term plan to get sales up and going.

We'll have to see if this all is stupidity or malice. Significant amounts of stupidity do look a lot like malice. Maybe I'm too much of a cynic to trust the gadget pushers...

What problem are the certificates solving?

Warm Braw

I can see you might need encryption to preserve the privacy of the user's choice of viewing, but you can do that without a certificate.

The domain name the iPlayer app connects to must be hardwired into the app itself, so presumably the certificate is acting as some form of identity check that the domain name hasn't been redirected somewhere else. But given that the iPlayer app has been provided by the BBC itself (or under its licence), you could perform the same check within the app without resorting to an external PKI service.

So is the PKI there to perform some other function, or is it just being used because the code is there already so it's easier than finding a domain-specific solution?

Lawyers... start your engines

Steve Davies 3

There will be a lot of people with some very expensive kit that has borked itself because of this issue. They will sue, sue and sue until they get a solution.

A lot of companies are walking blind into this mess. Some really don't give a F**k. They have your money and good luck trying to get any support.

If this gets bad enough the Politicians (who it seems are mostly Lawyers or PPE grads these days) will get involved which will only make things worse.

An awful lot of this kit is never connected to the interwebs so I'd like someone to explain why it needs security certificates in the first place.

OTOH, this is a disaster by design and as other comments have said this is all to get you to buy more stuff which will more than likely have even an even shorter lifespan before the same thing happens again.

Re: Lawyers... start your engines

Anonymous Coward

Any kit which isn't connected to the interwebs will presumably just carry on working as it is already, so there shouldn't be an issue in that situation?

Of course if they weren't so greedy ....

Lunatic Looking For Asylum

Why do we need encrypted/ssl connections to stream media ? I can turn a TV on and get it down an aerial and it is not encrypted, indeed everybody can snoop and see the traffic if they want.

What's the difference with streaming media, none. They could stream it over port 80 and it would still be more secure than the airwaves.

It's all down to DRM and them wanting to monetise the pap they produce.

Conveniently disguised planned obsolesence.

Simple solution

Wim Ton

That is why my companies' IoT products' certificates are valid to 31-12-9999. Our customers would be very upset if communication would suddenly cease.

Oh, and they are valid from 1-1-1970 to handle the case of the clock not set due to an empty battery.

Re: Simple solution

Anonymous Coward

That won't avoid the issue mentioned in the article - it's not the expiry date of _your_ cert that's the problem - it's the expiry date of the Certificate Authority's root cert, which your cert relies on.

Re: Simple solution

Alan J. Wylie

> it's the expiry date of the Certificate Authority's root cert

Except that no CA these days will issue a cert valid for more than 2 years. His must be self-signed.

Re: Simple solution

Wim Ton

For this reason we operate an own PKI. With the browsers restrictions on end certificates, customers have the risk of devices bricking themselves when stored too long.

Silence is the element in which great things fashion themselves.
-- Thomas Carlyle