Tech●●●●●Difficulty 4 of 5

How does your browser know that the padlock is not a fake?

Encryption is easy to do and hard to trust. Your browser relies on a few dozen organisations to vouch for every site, and in 2011 one of them was hacked.

▶ Start the story

The padlock means your browser checked a certificate, a digital document that certifies the ownership of a public key by the named website. A certificate authority, or CA, issues it and acts as a trusted third party, trusted both by the site's owner and by the visitor who relies on it.

Encryption alone is not enough. When you connect, your browser and the site use a handshake with an asymmetric cipher to establish a shared key, and then use that key to encrypt the rest of the conversation with a symmetric cipher. But a malicious party sitting on the route could pretend to be the target server, the classic man-in-the-middle attack. A certificate is what makes that fake detectable. Browsers include a built-in set of trusted CA certificates, and since the browser already holds each authority's public key, it can verify the signature on the certificate the site presents. An impostor could copy a real site's certificate, but without the matching private key it cannot create the signature needed to prove it is the real site.

What the padlock checks
  1. Step 1: Handshake starts

    Browser and site begin to set up a connection

  2. Step 2: Certificate

    The site presents a certificate signed by a CA

  3. Step 3: Trusted list

    The browser checks the signature against CAs it already trusts

  4. Step 4: Proof of the private key

    Only the real site can complete the handshake

  5. Step 5: Encrypted session

    Traffic is encrypted with a shared session key

The system has one structural weakness: any CA a browser trusts can issue certificates for any domain it likes, and they will be accepted as valid whether they are legitimate or not. In June 2011 the Dutch CA DigiNotar was hacked and issued hundreds of fraudulent certificates, some of which were used for man-in-the-middle attacks on Iranian Gmail users. After more than 500 fake certificates were found, browser makers blacklisted all DigiNotar certificates, and the company was declared bankrupt that September.

Quiz me

0/3

  1. 1.Why is encryption alone not enough to protect you from a man in the middle?
  2. 2.What is the "critical weakness" of the CA system that DigiNotar exposed?
  3. 3.What problem does Certificate Transparency address?

Recap

Encryption protects the line; certificates prove who is on the other end; public logs watch the signers.

💡 A trick to remember it · A padlock is a notary's stamp: it only means something while you trust the notary, so we now keep a public ledger of every stamp.

Surprising fact · Any trusted CA can issue a certificate for any domain, which is why DigiNotar's 2011 breach was so serious.

Sources (4)

No source, no claim. Every fact in this lesson (19 claims) cites at least one of these.

  1. [1]Transport Layer Security · Wikipedia
  2. [2]Certificate authority · Wikipedia
  3. [3]DigiNotar · Wikipedia
  4. [4]Certificate Transparency · Wikipedia
More lessons in 💻 Tech (3) See all tech lessons →

One more light on your map.

Get one lesson like this every day, about the things you love. Free, in two or five minutes.

Get the share card for this lesson ↗