pwshub.com

Google calls for halting use of WHOIS for TLS domain verifications

WHOWAS —

WHOIS data is unreliable. So why is it used in TLS certificate applications?

Google calls for halting use of WHOIS for TLS domain verifications

Getty Images

Certificate authorities and browser makers are planning to end the use of WHOIS data verifying domain ownership following a report that demonstrated how threat actors could abuse the process to obtain fraudulently issued TLS certificates.

TLS certificates are the cryptographic credentials that underpin HTTPS connections, a critical component of online communications verifying that a server belongs to a trusted entity and encrypts all traffic passing between it and an end user. These credentials are issued by any one of hundreds of CAs (certificate authorities) to domain owners. The rules for how certificates are issued and the process for verifying the rightful owner of a domain are left to the CA/Browser Forum. One "base requirement rule" allows CAs to send an email to an address listed in the WHOIS record for the domain being applied for. When the receiver clicks an enclosed link, the certificate is automatically approved.

Non-trivial dependencies

Researchers from security firm watchTowr recently demonstrated how threat actors could abuse the rule to obtain fraudulently issued certificates for domains they didn’t own. The security failure resulted from a lack of uniform rules for determining the validity of sites claiming to provide official WHOIS records.

Specifically, watchTowr researchers were able to receive a verification link for any domain ending in .mobi, including ones they didn’t own. The researchers did this by deploying a fake WHOIS server and populating it with fake records. Creation of the fake server was possible because dotmobiregistry.net—the previous domain hosting the WHOIS server for .mobi domains—was allowed to expire after the server was relocated to a new domain. watchTowr researchers registered the domain, set up the imposter WHOIS server, and found that CAs continued to rely on it to verify ownership of .mobi domains.

The research didn’t escape the notice of the CA/Browser Forum (CAB Forum). On Monday, a member representing Google proposed ending the reliance on WHOIS data for domain ownership verification “in light of recent events where research from watchTowr Labs demonstrated how threat actors could exploit WHOIS to obtain fraudulently issued TLS certificates."

The formal proposal calls for reliance on WHOIS data to “sunset” in early November. It establishes specifically that “CAs MUST NOT rely on WHOIS to identify Domain Contacts” and that “Effective November 1, 2024, validations using this [email verification] method MUST NOT rely on WHOIS to identify Domain Contact information.”

Since Monday’s submission, more than 50 follow-up comments have been posted. Many of the responses expressed support for the proposed change. Others have questioned the need for a change as proposed, given that the security failure watchTowr uncovered is known to affect only a single top-level domain.

An Amazon representative, meanwhile, noted that the company previously implemented a unilateral change in which the AWS Certificate Manager will fully transition away from reliance on WHOIS records. The representative told CAB Forum members that Google’s proposed deadline of November 1 may be too stringent.

“We got feedback from customers that for some this is a non-trivial dependency to remove,” the Amazon representative wrote. “It’s not uncommon for companies to have built automation on top of email validation. Based on the information we got I recommend a date of April 30, 2025.”

CA Digicert endorsed Amazon’s proposal to extend the deadline. Digicert went on to propose that instead of using WHOIS records, CAs instead use the WHOIS successor known as the Registration Data Access Protocol.

The proposed changes are formally in the discussion phase of deliberations. It’s unclear when formal voting on the change will begin.

Source: arstechnica.com

Related stories
1 week ago - The business outcomes of the AT&T and Microsoft cases bode poorly for the internet giant if a judge calls for stern measures up to and including a breakup.
1 month ago - Google is sticking with porcelain and obsidian colorways (white and black) for its new Fold even as the rest of the Pixel 9 series comes in a variety of colors.
1 day ago - Says Lina Khan in latest push to rein in Meta, Google, Amazon and pals Buried beneath the endless feeds and attention-grabbing videos of the modern internet is a network of data harvesting and sale that's far more vast than most people...
2 weeks ago - As companies like Apple, Google and Samsung load their devices with AI, many consumers are still unimpressed -- and unwilling to pay for those premium features.
3 weeks ago - Around 200 employees of DeepMind signed a letter urging the company to terminate its contracts with military customers. According to a report by Time, the letter was sent to Google's higher-ups earlier this year. However, executives have...
Other stories
1 minute ago - EA Sports FC 25 is now available for customers who pre-ordered the Ultimate Edition for $100, while the standard edition will launch on September 27 for $70.Read Entire Article
1 hour ago - What is the best internet provider in Michigan?Spectrum is CNET's top choice for internet service providers in Michigan. It's got fast speeds,...
2 hours ago - Qualcomm has approached fellow US chipmaker Intel in recent days about a possible takeover, the Wall Street Journal reported Friday.Intel has...
3 hours ago - Enlarge / Control Center has a whole new customization interface.Samuel Axon iOS 18 launched this week, and while its flagship feature (Apple...
3 hours ago - Spice up your texts with friends using animations, formatting, tapbacks and more. You can even bounce them off a satellite.