Skip to main navigation Skip to search Skip to main content

Mission accomplished? HTTPS security after diginotar

  • Johanna Amann
  • , Oliver Gasser
  • , Quirin Scheitle
  • , Lexi Brent
  • , Georg Carle
  • , Ralph Holz
  • Lawrence Berkeley National Laboratory
  • Technical University of Munich
  • University of Sydney

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

87 Scopus citations

Abstract

Driven by CA compromises and the risk of man-in-the-middle attacks, new security features have been added to TLS, HTTPS, and the web PKI over the past five years. These include Certificate Transparency (CT), for making the CA system auditable; HSTS and HPKP headers, to harden the HTTPS posture of a domain; the DNS-based extensions CAA and TLSA, for control over certificate issuance and pinning; and SCSV, for protocol downgrade protection. This paper presents the first large scale investigation of these improvements to the HTTPS ecosystem, explicitly accounting for their combined usage. In addition to collecting passive measurements at the Internet uplinks of large University networks on three continents, we perform the largest domain-based active Internet scan to date, covering 193M domains. Furthermore, we track the long-term deployment history of new TLS security features by leveraging passive observations dating back to 2012. We find that while deployment of new security features has picked up in general, only SCSV (49M domains) and CT (7M domains) have gained enough momentum to improve the overall security of HTTPS. Features with higher complexity, such as HPKP, are deployed scarcely and often incorrectly. Our empirical findings are placed in the context of risk, deployment effort, and benefit of these new technologies, and actionable steps for improvement are proposed. We cross-correlate use of features and find some techniques with significant correlation in deployment. We support reproducible research and publicly release data and code.

Original languageEnglish
Title of host publicationIMC 2017 - Proceedings of the 2017 Internet Measurement Conference
PublisherAssociation for Computing Machinery
Pages325-340
Number of pages16
ISBN (Electronic)9781450351188
DOIs
StatePublished - 1 Nov 2017
Event2017 ACM Internet Measurement Conference, IMC 2017 - London, United Kingdom
Duration: 1 Nov 20173 Nov 2017

Publication series

NameProceedings of the ACM SIGCOMM Internet Measurement Conference, IMC
VolumePart F131937

Conference

Conference2017 ACM Internet Measurement Conference, IMC 2017
Country/TerritoryUnited Kingdom
CityLondon
Period1/11/173/11/17

Keywords

  • CAA
  • CT
  • HPKP
  • HSTS
  • HTTPS
  • PKI
  • SCSV
  • TLS
  • X.509

Fingerprint

Dive into the research topics of 'Mission accomplished? HTTPS security after diginotar'. Together they form a unique fingerprint.

Cite this