News: 1613389273

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Let's Encrypt completes huge upgrade, can now rip and replace 200 million security certs in 'worst case scenario'

(2021/02/15)


In brief Internet Security Research Group nonprofit Let's Encrypt has massively upgraded its certification hardware and software so that it can delete and reissue all its certs in less than 24 hours.

Last April the certificate authority [1]was forced to kill three million HTTPS certs after a bug was found in its automated certificate management environment, about 2.6 per cent of its 150 million live certificate base. That caused some head-scratching.

[2]

"What if that bug had affected all of our certificates? That's more than 150 million certificates covering more than 240 million domains," [3]said Let's Encrypt exec director Josh Aas. "What if it had also been a more serious bug, requiring us to revoke and replace all certificates within 24 hours? That's the kind of worst case scenario we need to be prepared for."

After upgrading its network to fiber and replacing aging Intel big iron with the latest AMD Epyc chip, not to mention some cunning software changes, Let's Encrypt now says it can revoke and replace 200 million certificates in less than 24 hours, should a catastrophic security failure occur.

[4]

SentinelOne scoops up threat-data speedsters from ex-Googlers Scalyr

Machine-learning security specialist (and [5]apparent bane of RIM) SentinelOne has splurged $155m in cash and equities for 10-year-old startup Scalyr to try to speed up operations.

Scalyr was co-founded by former Google Docs architect Steve Newman after the Chocolate Factory bought his nascent cloud word processing biz [6]Writely in 2006 and turned it into the Gsuite we know and scream at today.

Newman set up Scalyr to use some of the analysis skills he'd honed on high-speed data analysis, and SentinelOne wants to use the technology to trawl through its vast pools of threat data quickly and smartly.

"We built Scalyr to solve critical data challenges for a cloud-first world," [7]said Newman. "I'm excited for the Scalyr team to become part of SentinelOne and solve one of the world's most pressing big data problems – cybersecurity."

TCP looking sickly

Nine out of 11 major TCP/IP stacks tested by security shop Forescout carry fatal flaws that would allow an attacker to perform a man-in-the-middle attack, according to [8]a report out this week.

The vulnerable stacks, predominantly used in IoT devices, are TI-NDKTCPIP, cycloneTCP, uC/TCP-IP, FNET, picoTCP, uIP, MPLAB Net, Nut/Net and Nucleus NET, with only lwIP and Nanostack proving solid under testing. All the failures were derived from issues with Initial Sequence Numbers (ISN) generation, the randomised digits that stop TCP collisions and ensure security.

"Most vendors have already issued patches and/or mitigation recommendations to users," the team said, adding that they had been disclosed in October. "The developers of Nut/Net are working on a solution, and Forescout has not received a response from the uIP developers."

The Supermicro case – a personal view

Three years after Bloomberg originally reported that Chinese spymasters were installing surreptitious silicon onto Supermicro motherboards, the story [9]is back .

Despite some having claimed to have seen the silicon, or have heard of its existence, we have yet to see a single chip that fits the bill and Supermicro and others are adamant that the claimed issue doesn't exist.

If 15 years writing about IT security have taught this hack anything, it's that you can never rule out a really cunning hack. But, at the same time, the Sagan standard must apply – "Extraordinary claims require extraordinary evidence."

[10]

To date we've seen no hard evidence that the Supermicro story is true, and plenty of evidence to suggest that it might be a case of mistaken identity – maybe subverting an existing chip via a firmware flaw that got misunderstood. We shall, hopefully, see. ®

Get our [11]Tech Resources



[1] https://www.theregister.com/2020/03/03/lets_encrypt_cert_revocation/

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YCqos-UYDmbcEw1FQQ2MYgAAAJY&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://letsencrypt.org/2021/02/10/200m-certs-24hrs.html

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YCqos-UYDmbcEw1FQQ2MYgAAAJY&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://www.theregister.com/2019/12/18/blackberry_sentinelone_non_compete_salesman_lawsuit/

[6] https://www.theregister.com/2006/03/10/google_writely/

[7] https://www.sentinelone.com/press/sentinelone-acquires-scalyr-to-revolutionize-xdr-and-security-analytics/

[8] https://www.forescout.com/company/blog/numberjack-forescout-research-labs-finds-nine-isn-generation-vulnerabilities-affecting-tcpip-stacks/

[9] https://www.theregister.com/2021/02/12/supermicro_bloomberg_spying/

[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YCqos-UYDmbcEw1FQQ2MYgAAAJY&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[11] https://whitepapers.theregister.com/

Crikey, someone thinking of failure cases...

John Robson

"Let's Encrypt now says it can revoke and replace 200 million certificates in less than 24 hours, should a catastrophic security failure occur."

That's more resilience than I expect any of the major pay-to-play-ers to have...

Re: Crikey, someone thinking of failure cases...

sev.monster

New arrows, looks like. Tested on your post. Enjoy the free point.

Sadly, points carry no value and are not tradable for fiat or beer, either of which would be fantastic.

Re: Crikey, someone thinking of failure cases...

Arthur the cat

Sadly, points carry no value

I thought points mean prizes?

Re: Crikey, someone thinking of failure cases...

Anonymous Coward

What they did was upgrade the operations per second license on their HSM's -- that's my guess.

Re: Crikey, someone thinking of failure cases...

Arthur the cat

It was more than just that. Read the linked article.

Re: Crikey, someone thinking of failure cases...

cipnt

Check their twitter updates. They got some bad ass hardware now:

https://twitter.com/letsencrypt/status/1354128984179675136

nijam

> To date we've seen no hard evidence that the Supermicro story is true

In a case like this, you can't prove a negative (proof by exhaustive enumeration not being viable), so the story will never go away.

Personally, I'm not blaming the Chinese, I think the chips were installed by the Loch Ness monster.

Without coffee he could not work, or at least he could not have worked in the
way he did. In addition to paper and pens, he took with him everywhere as an
indispensable article of equipment the coffee machine, which was no less
important to him than his table or his white robe.
-- Stefan Zweigs, Biography of Balzac