Let's Encrypt completes huge upgrade, can now rip and replace 200 million security certs in 'worst case scenario'
- Reference: 1613389273
- News link: https://www.theregister.co.uk/2021/02/15/in_brief_security/
- Source link:
Last April the certificate authority [1]was forced to kill three million HTTPS certs after a bug was found in its automated certificate management environment, about 2.6 per cent of its 150 million live certificate base. That caused some head-scratching.
[2]
"What if that bug had affected all of our certificates? That's more than 150 million certificates covering more than 240 million domains," [3]said Let's Encrypt exec director Josh Aas. "What if it had also been a more serious bug, requiring us to revoke and replace all certificates within 24 hours? That's the kind of worst case scenario we need to be prepared for."
After upgrading its network to fiber and replacing aging Intel big iron with the latest AMD Epyc chip, not to mention some cunning software changes, Let's Encrypt now says it can revoke and replace 200 million certificates in less than 24 hours, should a catastrophic security failure occur.
[4]
SentinelOne scoops up threat-data speedsters from ex-Googlers Scalyr
Machine-learning security specialist (and [5]apparent bane of RIM) SentinelOne has splurged $155m in cash and equities for 10-year-old startup Scalyr to try to speed up operations.
Scalyr was co-founded by former Google Docs architect Steve Newman after the Chocolate Factory bought his nascent cloud word processing biz [6]Writely in 2006 and turned it into the Gsuite we know and scream at today.
Newman set up Scalyr to use some of the analysis skills he'd honed on high-speed data analysis, and SentinelOne wants to use the technology to trawl through its vast pools of threat data quickly and smartly.
"We built Scalyr to solve critical data challenges for a cloud-first world," [7]said Newman. "I'm excited for the Scalyr team to become part of SentinelOne and solve one of the world's most pressing big data problems – cybersecurity."
TCP looking sickly
Nine out of 11 major TCP/IP stacks tested by security shop Forescout carry fatal flaws that would allow an attacker to perform a man-in-the-middle attack, according to [8]a report out this week.
The vulnerable stacks, predominantly used in IoT devices, are TI-NDKTCPIP, cycloneTCP, uC/TCP-IP, FNET, picoTCP, uIP, MPLAB Net, Nut/Net and Nucleus NET, with only lwIP and Nanostack proving solid under testing. All the failures were derived from issues with Initial Sequence Numbers (ISN) generation, the randomised digits that stop TCP collisions and ensure security.
"Most vendors have already issued patches and/or mitigation recommendations to users," the team said, adding that they had been disclosed in October. "The developers of Nut/Net are working on a solution, and Forescout has not received a response from the uIP developers."
The Supermicro case – a personal view
Three years after Bloomberg originally reported that Chinese spymasters were installing surreptitious silicon onto Supermicro motherboards, the story [9]is back .
Despite some having claimed to have seen the silicon, or have heard of its existence, we have yet to see a single chip that fits the bill and Supermicro and others are adamant that the claimed issue doesn't exist.
If 15 years writing about IT security have taught this hack anything, it's that you can never rule out a really cunning hack. But, at the same time, the Sagan standard must apply – "Extraordinary claims require extraordinary evidence."
[10]
To date we've seen no hard evidence that the Supermicro story is true, and plenty of evidence to suggest that it might be a case of mistaken identity – maybe subverting an existing chip via a firmware flaw that got misunderstood. We shall, hopefully, see. ®
Get our [11]Tech Resources
[1] https://www.theregister.com/2020/03/03/lets_encrypt_cert_revocation/
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YCqos-UYDmbcEw1FQQ2MYgAAAJY&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://letsencrypt.org/2021/02/10/200m-certs-24hrs.html
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YCqos-UYDmbcEw1FQQ2MYgAAAJY&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://www.theregister.com/2019/12/18/blackberry_sentinelone_non_compete_salesman_lawsuit/
[6] https://www.theregister.com/2006/03/10/google_writely/
[7] https://www.sentinelone.com/press/sentinelone-acquires-scalyr-to-revolutionize-xdr-and-security-analytics/
[8] https://www.forescout.com/company/blog/numberjack-forescout-research-labs-finds-nine-isn-generation-vulnerabilities-affecting-tcpip-stacks/
[9] https://www.theregister.com/2021/02/12/supermicro_bloomberg_spying/
[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YCqos-UYDmbcEw1FQQ2MYgAAAJY&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[11] https://whitepapers.theregister.com/
Re: Crikey, someone thinking of failure cases...
New arrows, looks like. Tested on your post. Enjoy the free point.
Sadly, points carry no value and are not tradable for fiat or beer, either of which would be fantastic.
Re: Crikey, someone thinking of failure cases...
Sadly, points carry no value
I thought points mean prizes?
Re: Crikey, someone thinking of failure cases...
What they did was upgrade the operations per second license on their HSM's -- that's my guess.
Re: Crikey, someone thinking of failure cases...
It was more than just that. Read the linked article.
Re: Crikey, someone thinking of failure cases...
Check their twitter updates. They got some bad ass hardware now:
https://twitter.com/letsencrypt/status/1354128984179675136
> To date we've seen no hard evidence that the Supermicro story is true
In a case like this, you can't prove a negative (proof by exhaustive enumeration not being viable), so the story will never go away.
Personally, I'm not blaming the Chinese, I think the chips were installed by the Loch Ness monster.
Crikey, someone thinking of failure cases...
"Let's Encrypt now says it can revoke and replace 200 million certificates in less than 24 hours, should a catastrophic security failure occur."
That's more resilience than I expect any of the major pay-to-play-ers to have...