{"id":3606,"date":"2017-03-01T10:35:18","date_gmt":"2017-03-01T15:35:18","guid":{"rendered":"https:\/\/www.thesslstore.com\/blog\/?p=3606"},"modified":"2023-04-10T17:11:59","modified_gmt":"2023-04-10T21:11:59","slug":"intermediate-certificate-fingerprinting","status":"publish","type":"post","link":"https:\/\/www.thesslstore.com\/blog\/intermediate-certificate-fingerprinting\/","title":{"rendered":"Fingerprinting Technique Identifies Based On Intermediate Certificates"},"content":{"rendered":"<h2>Intermediate certificate fingerprinting&nbsp;is unique to Firefox.<\/h2>\n<p>To make a successful HTTPS connection, a browser needs to be able to build a chain from the website\u2019s SSL certificate to the root CA certificate. Intermediate certificates make up the middle of this chain. There will always be at least one of them, but there can be more.<\/p>\n<p>The chaining process is straightforward if the website has configured its server properly and directly sends all the necessary Intermediate certificates to the browser. But missing, or otherwise misconfigured intermediates is one of the most common HTTPS configuration errors.<\/p>\n<figure id=\"attachment_3613\" aria-describedby=\"caption-attachment-3613\" style=\"width: 975px\" class=\"wp-caption alignnone\"><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-3613\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/03\/CertificateChain.png\" alt=\"Intermediate Certificate Fingerprinting\" width=\"975\" height=\"555\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/03\/CertificateChain.png 975w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/03\/CertificateChain-300x171.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/03\/CertificateChain-768x437.png 768w\" sizes=\"auto, (max-width: 975px) 100vw, 975px\" \/><figcaption id=\"caption-attachment-3613\" class=\"wp-caption-text\">A visualization of a Certificate Chain where the webserver has not provided the Intermediate certificate. Courtesy of shiftordie.de.<\/figcaption><\/figure>\n<p>To prevent the web from being a mess of certificate errors, browsers came up with ways to deal with those misconfigurations. Firefox does this by building a local cache of Intermediates it receives from properly configured sites. It can then look to that cache for the proper certificate when making other connections.<\/p>\n<p>There are, however, a couple of downsides to Firefox compensating for missing Intermediates. For one, it creates the illusion that a misconfigured site is working properly. An inexperienced server admin may not realize that their site\u2019s HTTPS connection is only working properly because of his browser\u2019s cache.<\/p>\n<p>The other downside is that a researcher has found a way to fingerprint users based on the uniqueness of their specific cache.<\/p>\n<p>This fingerprinting technique works by loading resources from a variety of misconfigured websites which don\u2019t have properly configured certificate chains, each website using certificates from different CAs. If the resource can be successfully loaded, it means that your Firefox browser already had the needed Intermediate(s) in its cache. If it can\u2019t be loaded, Firefox didn\u2019t make the HTTPS connection because it did not have the Intermediate. Which Intermediates were and were not cached can then be recorded and saved, and if the data is unique enough, it can build a unique fingerprint.<\/p>\n<p>There are loads of CAs out there. You likely know the big ones like Symantec, Comodo, and GoDaddy. But do you know HARICA? Also known as the Hellenic Academic &amp; Research Institutions Certificate Authority, which serves Greece\u2019s academic community? No?<\/p>\n<p>These niche CAs serve specific regions, government offices, and other specialized communities. They have root certificates residing in millions of computers across the globe, even though it&#8217;s unlikely most users will ever encounter one of their certificates.<\/p>\n<p>So while having the cached Intermediate for any of Symantec\u2019s roots may not do much to uniquely identify you, the Intermediates for HARICA of Hongkong\u2019s Postal service can.<\/p>\n<p>Alexander Klink, <a href=\"https:\/\/shiftordie.de\/blog\/2017\/02\/21\/fingerprinting-firefox-users-with-cached-intermediate-ca-certificates-fiprinca\/\">who created this technique, wrote<\/a> on his blog, \u201ccertain CAs have customers mostly in one country or region, or might have even more specific use-cases which lets you infer even more information \u2212 i.e. a user who has the \u00bbDeutsche Bundestag CA\u00ab cached [Ed: The Bundestag is one of Germany\u2019s legislative bodies, like the US House of Representatives] is most probably located in Germany and probably at least somewhat interested in politics.\u201d<\/p>\n<p>Klink noted some of the different uses for the technique, including linking a user to a Private Browsing session (since they share the same cache) and detecting if the client device is a malware analysis sandbox, \u201cwhich would probably have none or very few of the common intermediates cached.\u201d<\/p>\n<p>Unlike other browsers, Firefox does not perform <a href=\"https:\/\/www.thesslstore.com\/blog\/aia-fetching\/\">AIA fetching<\/a>, which uses embedded information in the server\u2019s certificate to know where to get a copy of the Intermediates needed. Ironically, Firefox avoided implementing AIA fetching because it has its own privacy downsides, and instead opted to use a cache which made the browser vulnerable to this fingerprinting technique.<\/p>\n<p>Google Chrome uses AIA fetching which renders it immune to this technique. Because Chrome can simply download the needed Intermediate during the connection, it isn\u2019t possible to build a list of what Intermediates it has previously encountered.<\/p>\n<p>Klink built a proof of concept which <a href=\"https:\/\/fiprinca.0x90.eu\/poc\/\" rel=\"nofollow\">allows you to see this new technique in action<\/a> (You will, of course, need to visit the page in Firefox). The test looks for 325 different Intermediate certificates.<\/p>\n<p>Earlier this year, Firefox <a href=\"https:\/\/www.forbes.com\/sites\/leemathews\/2017\/01\/16\/firefox-update-kills-sneaky-tracking\/#4bff88d911c9\" rel=\"nofollow\">implemented a \u201cfont whitelist\u201d<\/a> to combat a fingerprinting technique which tried to identify you via your computer\u2019s supported fonts.<\/p>\n<p>Firefox developers <a href=\"https:\/\/bugzilla.mozilla.org\/show_bug.cgi?id=1334485\" rel=\"nofollow\">noted<\/a> that defending against this new Intermediate caching fingerprinting technique may not be so easy, as it would likely require reducing its functionality or disabling the cache altogether. For now, they are not planning any changes.<\/p>\n<p>Researchers from Lehigh University in Pennsylvania recently created a fingerprinting method <a href=\"https:\/\/arstechnica.com\/security\/2017\/02\/now-sites-can-fingerprint-you-online-even-when-you-use-multiple-browsers\/\" rel=\"nofollow\">that can uniquely identify your computer from its graphic rendering capabilities<\/a>, allowing tracking across different browsers. Fingerprinting methods are becoming increasingly complex, often relying on hardware\/software capabilities and settings to identify you without even needing to look at your specific habits or browsing history.<\/p>\n\n<span style=\"--tl-form-height-m:150.25px;--tl-form-height-t:121.4583px;--tl-form-height-d:121.4583px;\" class=\"tl-placeholder-f-type-shortcode_12753 tl-preload-form\"><span><\/span><\/span>","protected":false},"excerpt":{"rendered":"<p>Intermediate certificate fingerprinting&nbsp;is unique to Firefox. To make a successful HTTPS connection, a browser needs to be able to build a chain from the website\u2019s SSL certificate to the root&#8230;<\/p>\n","protected":false},"author":2,"featured_media":3615,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":"","tve_updated_post":"","tve_custom_css":"","tve_user_custom_css":"","tve_globals":{},"tcb2_ready":0,"tcb_editor_enabled":0,"tve_landing_page":"","_tve_header":"","_tve_footer":""},"categories":[16],"tags":[237,732,731,170,196,467],"class_list":["post-3606","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-hashing-out-cyber-security","tag-aia-fetching","tag-certificate-chain","tag-fingerprinting","tag-https","tag-intermediate-certificates","tag-ssltls","post-with-tags"],"views":10733,"jetpack_featured_media_url":"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2017\/03\/iStock-149480786.jpg","_links":{"self":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/3606","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/comments?post=3606"}],"version-history":[{"count":0,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/3606\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media\/3615"}],"wp:attachment":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media?parent=3606"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/categories?post=3606"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/tags?post=3606"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}