Making SSL User Friendly
Bruce Schneier posted about a phishing scheme that “defeats” two factor authentication. It does so by being a man-in-the-middle. Other than that I agree with most commenters that it’s user stupidity, not a failure of two-factor auth, it brings up two points:
1. Two-factor needs to be combined with “two-way”
2. Security mechanisms already in place need to be more user friendly.
When I say two-factor authentication needs to be “two-way”, I mean that both sides need to prove themselves, not just one. In this case, the user gives something he knows and something he has to the web site, but the web site doesn’t quite return the favor. The web site is giving somethings it has (an SSL certificate). Theoretically, it’s also something the server knows (typing a passphrase to bring up the server and unlock it’s SSL key) but how many people actually do that? Most just use a passwordless key. The web site needs to prove itself to the user. And here’s where the user stupidity comes in – you would hope that Citibank has a legitimate SSL certificate that the MITM cannot spoof, so why did the user trust it?
This brings me to my second point. The mechanism for the web server to prove who it is is already there – it’s called SSL. The problem is, most users don’t know how to take advantage of SSL.
The concepts are simple – to someone who understands trust models. To my mom? It’s just an annoying button she has to click to get to the web page she wants to go to.
Most web browsers verify the server certificate, and warn the user if there’s a problem. But that warning is cryptic and unless the user is aware of what is happening, they just click “continue”. And how many people have looked at the default Trust Roots in Windows lately? And not just looked at them, but determined whether to trust them or not? I’m willing to bet, very few people.
If a phishing site manages to get signed by one of those CAs or a subordinate CA, there’s not even a warning.
And try explaining to your mom that she has to click here, then here, then here, and make sure that A and B match. If you’ve ever tried that, you know what I’m talking about.
If the ideas and concepts of SSL are made more user friendly, more people will be able to detect that the MITM is not the bank they think they’re logging onto.
User stupidity will always be around, but if we as security professionals do our best to make the security more user friendly and easier to use and understand, maybe we can reduce some of these schemes.