[PATCH] wget: don't silently ignore certificate validation

tiggersWelt.net (Support) support at tiggerswelt.net
Sat May 26 23:18:22 UTC 2018


Good evening Denys,

I agree with you that this patch is unacceptable, I also agree that
everyone who is complaining about the situation should send patches, but
I strongly disagree that it is valid to break security to keep "common
use cases" working. Using security-techniques like https should never
give a false impression of being secure while implementing it wrong.

I remember that I've missed HTTPS-Support in wget for years and was very
happy to see it being implemented back in 2014/2015. I've never had a
look at the code nor its documentation, because I had trust that busybox
is doing things right. I regret this was a personal mistake by myself.

Most encryption is worth nothing without authentication. If
authentication is skipped, encryption is broken by design and should not
be implemented at all. It's valid to add a parameter to switch off
authentication, but the default should verify that everything is
correct. If you think it's ok to skip authentication, we could also skip
checking bounds of a string because for common use cases there is
everything okay and no checks need to be applied.

To be constructive I've taken Jakub's Patch and rewrote it a bit to lead
to a small but fast improvement: Added verification-options to openssl
s_client helper and fail hard if the helper could not be spawned. This
may be switched off using "--no-check-certificate".

Internal wrapper and FTPS keep the old broken state and continue to work
without authentication while s_client-helper will fail whenever
verification fails. I remember that GNU wget also switched to this
behavior some years ago, so it should be suitable for any common case.
The broken state regarding the internal wrapper should be documented,
but I'm too tired to do this. The attached patch fixes this issue for me
and would restore some of my trust if being applied.


Kind regards,

Bernd


Am 26.05.2018 um 19:34 schrieb Denys Vlasenko:
> wget should work for common use cases.
> Such as downloading sources of kernels, gcc and such.
> From build scripts, not only by hand.
> Without having to modify said scripts.
> Your patch breaks that.
> NAK.
> 
> I don't care that security people are upset.
> They are paranoid, it's part of their profession.
> It does not mean everybody else have to be as paranoid.
> 
> If you have a patch which adds actual cert checking
> and thus does not introduce regressions, please post it.
> 
> 
> On Sat, May 26, 2018 at 6:38 PM,  <jakub at jirutka.cz> wrote:
>>> //config:       If you still think this is unacceptable, send patches.
>>
>>
>> That’s exactly what I did.
>> http://lists.busybox.net/pipermail/busybox/2018-May/086444.html
>>
>> Jakub
>>
>>
>> On 2018-05-26 17:54, Denys Vlasenko wrote:
>>>
>>> On Sat, May 26, 2018 at 5:39 PM,  <jakub at jirutka.cz> wrote:
>>>>>>
>>>>>> That's a crime against security!
>>>>>
>>>>>
>>>>> Say what?
>>>>
>>>>
>>>> That’s a hyperbole. The thing is that when you don’t verify the peer’s
>>>> certificate, then you’re vulnerable to MitM attack with fake certificate
>>>> injection. The whole SSL/TLS is totally useless in that moment. It’s more
>>>> or
>>>> less like putting the door’s key under the carpet right in front of the
>>>> door.
>>>>
>>>> Allowing to bypass/ignore certificate verification is ok-ish in some
>>>> situations, but only when the user do it consciously, using explicit
>>>> option
>>>> such as --no-check-certificate, not silently as the default option.
>>>
>>>
>>> wget.c:
>>>
>>> //config:       If you still think this is unacceptable, send patches.
>>> //config:
>>> //config:       If you still think this is unacceptable, do not want to
>>> send
>>> //config:       patches, but do want to waste bandwidth explaining how
>>> wrong
>>> //config:       it is, you will be ignored.
> _______________________________________________
> busybox mailing list
> busybox at busybox.net
> http://lists.busybox.net/mailman/listinfo/busybox
> 

-- 
    \\\||///
  \\  - -  //
   (  @ @  )
-oOo--( )--oOo-------------------------------------------------------
 tiggersWelt.net                                 www.tiggersWelt.net
 Inhaber Bernd Holzmüller                       info at tiggerswelt.net
                                            Büro: 07 11 / 550 425-90
 Marktstraße 57                              Fax: 07 11 / 550 425-99
 70372 Stuttgart

 Impressum: https://tiggerswelt.net/impressum
-------------- next part --------------
A non-text attachment was scrubbed...
Name: 0001-Enabled-certificate-verification-when-tunneling-wget.patch
Type: text/x-patch
Size: 4089 bytes
Desc: not available
URL: <http://lists.busybox.net/pipermail/busybox/attachments/20180527/1c50ea9b/attachment-0001.bin>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 195 bytes
Desc: OpenPGP digital signature
URL: <http://lists.busybox.net/pipermail/busybox/attachments/20180527/1c50ea9b/attachment-0001.asc>


More information about the busybox mailing list